Sceawere
Vulnerability Detail
CVE-2026-61211Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle RDBMS DBMS_CLOUD Privilege Escalation
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Database Server
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-07-21T22:18:52.790Z",
"pubdate": "2026-07-21T22:18:52.790Z",
"executiveSummary": "This vulnerability exists within the RDBMS component of the Oracle Database Server, specifically affecting the DBMS_CLOUD package.\nThe flaw allows a low-privileged authenticated attacker to achieve a full takeover of the RDBMS instance.\nThe vulnerability is characterized by a high degree of exploitability, requiring only low-level privileges (Execute DBMS_CLOUD) and standard network access via Oracle Net.\nDue to the scope change (S:C) associated with this vulnerability, a successful exploit can compromise not only the database but also potentially impact additional integrated products and infrastructure.\nWith a CVSS 3.1 base score of 9.9, this vulnerability poses a critical risk to Confidentiality, Integrity, and Availability.\nThe vulnerability requires no user interaction (UI:N) and can be executed remotely over the network, making it a high-priority threat for database administrators.",
"technicalDetails": "The vulnerability resides within the RDBMS component of the Oracle Database Server, specifically targeting the DBMS_CLOUD PL/SQL package.\nThe root cause involves improper authorization checks or input validation within the DBMS_CLOUD execution context, which can be leveraged by an attacker with the 'Execute DBMS_CLOUD' privilege to bypass security controls and execute arbitrary commands or operations with elevated privileges.\nAffected versions include Oracle Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2.\nThe attack vector is network-based (AV:N), utilizing the Oracle Net protocol to interact with the database instance. The attack complexity is low (AC:L), as there are no complex environmental requirements or race conditions identified in the vulnerability description.\nA successful attack flow typically involves an attacker with an existing low-privileged database account possessing the requisite execute privilege on DBMS_CLOUD. The attacker sends specially crafted requests to the RDBMS via Oracle Net that exploit the insecure logic within the DBMS_CLOUD package.\nBecause the vulnerability involves a scope change (S:C), the impact is not limited to the local database schema. The attacker can leverage the compromised RDBMS to pivot into external systems, cloud services, or integrated infrastructure that the database interacts with, effectively escalating the breach beyond the database boundary.\nPost-exploitation, the attacker achieves full control (takeover) of the RDBMS, allowing for complete unauthorized access to data, modification of system configurations, disruption of services (Denial of Service), and potential lateral movement into the hosting environment.\nThere is no requirement for user interaction, meaning the attack can be fully automated or performed silently by a malicious actor once access is established via the network.\nThe combination of low privilege requirements (PR:L) and high impact (C:H/I:H/A:H) makes this a critical flaw in the RDBMS security architecture, necessitating immediate assessment of the DBMS_CLOUD usage across the enterprise database fleet."
}