CVE-2026-21999: Infoleak
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise XML Database. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all XML Database accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21999?
The severity of CVE-2026-21999 is rated medium with a score of 5.3.
How do I fix CVE-2026-21999?
To fix CVE-2026-21999, it is recommended to apply the latest security patches provided by Oracle for the affected versions.
What components are affected by CVE-2026-21999?
CVE-2026-21999 affects the XML Database component of Oracle Database Server in versions 23.4.0 to 23.26.1.
Can CVE-2026-21999 be exploited remotely?
Yes, CVE-2026-21999 can be exploited remotely by an unauthenticated attacker with network access via HTTPS.
Does CVE-2026-21999 require human interaction to exploit?
Yes, exploitation of CVE-2026-21999 requires human interaction for successful attacks.