CVE-2026-83072
moderateAuthenticated Data Manipulation Flaw in Oracle E-Business Suite Applications Framework
The Oracle Applications Framework component of Oracle E-Business Suite contains an easily exploitable flaw in the Search Bean (including Advanced) component. A low-privileged attacker with network access via HTTP who triggers the flaw can compromise the Applications Framework, gaining unauthorized ability to create, delete, or modify critical data as well as read access to critical data or all framework-accessible data. Deployments running E-Business Suite releases 12.2.3 through 12.2.15 are affected. The issue carries a CVSS 3.1 base score of 8.1 (high), is not on CISA's Known Exploited Vulnerabilities list, and no public proof of concept is known, so exploitation in the wild is not currently observed.
What to do: Apply the Oracle Critical Patch Update that remediates this flaw — every listed release (12.2.3–12.2.15) is affected, so patching is required rather than a version upgrade within that range. Restrict HTTP access to EBS/OAF pages, especially self-service and search endpoints, to trusted networks or VPN, and minimize low-privilege account sprawl since exploitation requires only an authenticated session. Review audit logs for anomalous Search Bean / Advanced Search activity and unexpected data changes made by low-privilege users.
| Oracle Applications Framework (Oracle E-Business Suite), component: Search Bean [Incl. Advanced] | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Advanced]). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.