{
  "cve": "CVE-2026-83160",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[23.4.0,23.26.3]"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "product": "database_-_rdbms",
        "vendor": "oracle"
      },
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[23.4.0,23.26.3]"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "Oracle Database Server",
          "source": "cna",
          "vendor": "Oracle Corporation"
        },
        "product": "database_server",
        "vendor": "oracle"
      }
    ],
    "created": "2026-09-17T01:45:06.800315+00:00",
    "title": "Privilege Escalation in Oracle Database RDBMS Allows Low-Privileged Network Attackers to Take Over the Database",
    "updated": "2026-09-20T10:00:09.754791+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$database_-_rdbms",
      "oracle$PRODUCT$database_server"
    ]
  },
  "epss": {
    "score": 0.00417
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-09-15T20:03:41.190000+00:00",
    "description": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 8.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/83xxx/CVE-2026-83160.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-17T15:17:05.071000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$database_-_rdbms"
    ],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [],
    "created": "2026-09-15T20:18:26.893000+00:00",
    "description": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 8.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-83160.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-17T16:18:06.280000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-284"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-09-15T20:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "oracle",
              "oracle$PRODUCT$database_-_rdbms"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "oracle",
                "oracle$PRODUCT$database_-_rdbms"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://www.oracle.com/security-alerts/cspusep2026.html"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 8.8,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "68fa2d26-6ced-4308-b381-2d143bf27fa1"
      },
      {
        "created": "2026-09-17T02:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "Oracle Database RDBMS Vulnerability Allows Low-Privilege Takeover",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-269",
                "CWE-284"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "3c2fdd0a-0f48-4080-8d73-d75ec7b5f0d5"
      },
      {
        "created": "2026-09-17T08:15:00+00:00",
        "data": [
          {
            "details": [
              "oracle$PRODUCT$database_server"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "oracle$PRODUCT$database_server"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "85c4dea0-7ed8-4de4-85e3-9e6bc34a21c8"
      },
      {
        "created": "2026-09-17T16:30:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "ae8328c5-5952-4ef1-93c4-a8f16da4f532"
      },
      {
        "created": "2026-09-18T21:30:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Oracle Database RDBMS Vulnerability Allows Low-Privilege Takeover"
            },
            "type": "title"
          },
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-269"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "786fcd5c-3a85-45be-9dce-eea888d9943c"
      },
      {
        "created": "2026-09-20T10:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Privilege Escalation in Oracle Database RDBMS Allows Low-Privileged Network Attackers to Take Over the Database",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "f61fe9d0-2a31-4536-af59-d1bddec36782"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre"
      ]
    },
    "created": {
      "data": "2026-09-15T20:03:41.190000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 8.8,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00417
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.oracle.com/security-alerts/cspusep2026.html"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "Privilege Escalation in Oracle Database RDBMS Allows Low-Privileged Network Attackers to Take Over the Database",
      "provider": "enrichment"
    },
    "updated": {
      "data": "2026-09-20T10:00:09.754791+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "oracle",
        "oracle$PRODUCT$database_-_rdbms",
        "oracle$PRODUCT$database_server"
      ],
      "providers": [
        "mitre",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-284"
      ],
      "providers": [
        "nvd",
        "vulnrichment"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-09-15T20:03:41.190000+00:00",
    "description": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-09-17T14:58:36.511000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/83xxx/CVE-2026-83160.json",
    "weaknesses": [
      "CWE-284"
    ]
  }
}