Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspusep2026.html |
|
Tue, 15 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle XML Developers Kit component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having XDKC privilege with network access via Oracle Net to compromise Oracle XML Developers Kit. Successful attacks of this vulnerability can result in takeover of Oracle XML Developers Kit. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle database - E Xml Developers Kit |
|
| CPEs | cpe:2.3:a:oracle:database_-_e_xml_developers_kit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle database - E Xml Developers Kit |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-09-15T20:03:39.942Z
Reserved: 2026-08-31T15:40:57.343Z
Link: CVE-2026-83156
No data.
Status : Received
Published: 2026-09-15T20:18:26.417
Modified: 2026-09-15T20:18:26.417
Link: CVE-2026-83156
No data.
OpenCVE Enrichment
No data.
No weakness.