---
id: CVE-2026-83088
title: Vulnerability in the RDBMS component of Oracle Database Server
summary: >-
  Vulnerability in the RDBMS component of Oracle Database Server.  Supported
  versions that are affected are 23.4.0-23.26.3. Easily exploitable
  vulnerability allows low privileged attacker having Authenticated User
  privilege with network ac…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'
cwe:
  - CWE-284
vendor: Oracle Corporation
product: Oracle Database Server
affected:
  - oracle_database_server >= 23.4.0 <= 23.26.3
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:40:00.317'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-83088'
references:
  - url: 'https://www.oracle.com/security-alerts/cspusep2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T17:55:57.550756Z'
ingestedAt: '2026-09-15T20:44:02.451Z'
epss: 0.00368
epssPercentile: 0.27884
---

## Overview

Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS.  While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS. CVSS 3.1 Base Score 7.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
