EIP-2026-117731

PRE-CVE

Oracle Database PL/SQL Statement - Multiple SQL Injections s

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117731. PoCs published by Esteban Fayo.

AI-analyzed exploit summary This exploit demonstrates SQL injection techniques in Oracle databases, including privilege escalation to SYS user, OS command execution, and file upload via Java stored procedures. It leverages a vulnerable PL/SQL procedure (`SYS.SQLIVULN`) to inject malicious payloads.

Description

Oracle Database PL/SQL Statement - Multiple SQL Injections s

Exploits (1)

exploitdb WORKING POC VERIFIED
by Esteban Fayo · localwindows
https://www.exploit-db.com/exploits/933

This exploit demonstrates SQL injection techniques in Oracle databases, including privilege escalation to SYS user, OS command execution, and file upload via Java stored procedures. It leverages a vulnerable PL/SQL procedure (`SYS.SQLIVULN`) to inject malicious payloads.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Oracle Database (version not specified)
Auth required
Prerequisites: Low-privileged database user access · Presence of vulnerable PL/SQL procedure (`SYS.SQLIVULN`)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026