importantSYS.SOURCE: The Hacker News• 2026-08-06T14:49:23+05:30
Oracle Database Exploit Uses SQL Injection to Achieve Windows SYSTEM Access via Java Compiling
Attackers exploited a SQL injection vulnerability in an Oracle database to compile Java code, achieving Windows SYSTEM-level access without writing files to disk. The technique leverages Oracle's embedded Java Virtual Machine and requires input validation and privilege control to mitigate.
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine.
Huntress, which tracks the toolkit as khunt,
*** END OF TRANSMISSION ***