ZeroHour

CVE-2026-83082

moderate

High-Privilege Account Takeover in Oracle E-Business Suite Marketing (Audience)

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83082 is a vulnerability in the Audience component of Oracle Marketing within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is easily exploitable by an attacker who already holds high privileges and has network access via HTTP to the EBS environment, allowing them to fully compromise the Oracle Marketing product. A successful attack results in a complete takeover of Oracle Marketing, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). Organizations running affected E-Business Suite 12.2.3-12.2.15 deployments with the Marketing product exposed to authenticated users are at risk, though the high-privilege prerequisite significantly narrows the attacker pool. There is no known public proof of concept, the CVE is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83082 to all E-Business Suite 12.2.3-12.2.15 environments running Oracle Marketing. Because exploitation requires high privileges over HTTP, audit and minimize privileged Marketing/Audience accounts, enforce least-privilege role assignment, and restrict HTTP access to EBS via network segmentation or VPN. Review authentication and administrative audit logs for unexpected activity by privileged marketing users on the Audience component.

Affected
Oracle E-Business Suite (Oracle Marketing, Audience component)12.2.3-12.2.15
Estimated exposure
moderate≈ tens of thousands of organizations run E-Business Suite 12.2, with only a few thousand EBS instances internet-exposed; subset with Oracle Marketing licensed… — E-Business Suite is deployed at tens of thousands of enterprises globally, and public internet scans (e.g., Shodan/FOFA) have historically shown only a few thousand internet-reachable EBS instances, most of which sit behind VPNs or reverse…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in takeover of Oracle Marketing. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.