ZeroHour

CVE-2026-83080

niche

Authenticated Account-Takeover Flaw in Oracle Banking Branch Reports (14.5-14.9)

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83080 is a difficult-to-exploit vulnerability in the Reports component of Oracle Banking Branch, part of Oracle Financial Services Applications. It allows a low-privileged attacker with network access via HTTP to compromise the application, but successful attacks require human interaction from a person other than the attacker (e.g., a victim user being tricked into performing some action, likely via social engineering). A successful attack can result in a full takeover of Oracle Banking Branch, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.1, vector AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H). Affected installations are Oracle Banking Branch versions 14.5.0.0.0 through 14.9.0.0.0, typically deployed inside banks and other financial institutions. No public proof of concept is known, the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83080 to all Oracle Banking Branch installations running versions 14.5.0.0.0 through 14.9.0.0.0, prioritizing instances where low-privilege user accounts and the Reports component are exposed over HTTP. Restrict network access to the Reports component to trusted users and segments, and review audit logs for anomalous activity by low-privileged accounts. Because exploitation requires victim interaction, reinforce user-awareness training against social-engineering attempts targeting branch and back-office staff.

Affected
Oracle Banking Branch (Oracle Financial Services Applications, component: Reports)14.5.0.0.0-14.9.0.0.0
Estimated exposure
nicheLikely hundreds to low thousands of bank deployments worldwide (order of magnitude: ~10^2-10^3 installations, each serving many branch users) — Oracle Banking Branch is enterprise banking software licensed per financial institution, and Oracle Financial Services Applications overall serve a relatively small global customer base of banks (roughly in the hundreds to low thousands),…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Branch. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Branch. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.