CVE-2025-8107

MEDIUM

OceanBase <Oracle Mode - Privilege Escalation

Title source: llm

Description

In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.

Scores

CVSS v3 6.3
EPSS 0.0005
EPSS Percentile 15.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-269 CWE-668
Status draft

Timeline

Published Jul 24, 2025
Tracked Since Feb 18, 2026