EIP-2026-103799

PRE-CVE

Oracle 10g - SYS.DBMS_CDC_IMPDP.BUMP_SEQUENCE PL / SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103799. PoCs published by Joxean Koret.

AI-analyzed exploit summary This exploit leverages SQL injection in Oracle10g's DBMS_CDC_IMPDP.BUMP_SEQUENCE procedure to inject malicious SQL commands, granting elevated privileges (DBA) to the attacker. The payload manipulates the SEQUENCE_NAME parameter to execute arbitrary SQL, specifically inserting a privileged entry into sys.sysauth$.

Description

Oracle 10g - SYS.DBMS_CDC_IMPDP.BUMP_SEQUENCE PL / SQL Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by Joxean Koret · textlocalmultiple
https://www.exploit-db.com/exploits/3177

This exploit leverages SQL injection in Oracle10g's DBMS_CDC_IMPDP.BUMP_SEQUENCE procedure to inject malicious SQL commands, granting elevated privileges (DBA) to the attacker. The payload manipulates the SEQUENCE_NAME parameter to execute arbitrary SQL, specifically inserting a privileged entry into sys.sysauth$.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Oracle Database 10g R1 and R2 (prior to CPU Oct 2006)
Auth required
Prerequisites: CREATE SESSION privilege
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026