EIP-2026-103798

PRE-CVE

Oracle 10g - 'SYS.LT.COMPRESSWORKSPACETREE' SQL Injection (2)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103798. PoCs published by Sumit Siddharth.

AI-analyzed exploit summary This exploit leverages cursor injection in Oracle Database to grant DBA privileges to the 'scott' user without requiring CREATE FUNCTION privileges. It uses DBMS_SQL.OPEN_CURSOR and SYS.LT procedures to execute arbitrary SQL commands via a crafted workspace name.

Description

Oracle 10g - 'SYS.LT.COMPRESSWORKSPACETREE' SQL Injection (2)

Exploits (1)

exploitdb WORKING POC VERIFIED
by Sumit Siddharth · textlocalmultiple
https://www.exploit-db.com/exploits/9072

This exploit leverages cursor injection in Oracle Database to grant DBA privileges to the 'scott' user without requiring CREATE FUNCTION privileges. It uses DBMS_SQL.OPEN_CURSOR and SYS.LT procedures to execute arbitrary SQL commands via a crafted workspace name.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Oracle Database (version not specified, likely older versions)
Auth required
Prerequisites: Access to a database account with execute permissions on SYS.LT procedures · Oracle Database with vulnerable SYS.LT package
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026