ZeroHour

CVE-2026-83083

moderate

Authenticated Data Access Flaw in Oracle Marketing (E-Business Suite) Audience Component

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

Oracle E-Business Suite's Oracle Marketing product (Audience component) contains an easily exploitable vulnerability in versions 12.2.3 through 12.2.15 that lets a low-privileged authenticated attacker with network access via HTTP compromise Oracle Marketing. Because the flaw carries a scope change (S:C), successful attacks may also significantly impact additional products beyond Oracle Marketing itself. A successful attacker gains unauthorized access to critical data or complete read access to all Oracle Marketing-accessible data, along with unauthorized update, insert, or delete access to some of that data; availability is not impacted (CVSS 3.1: 8.5). Any organization running the affected 12.2.3–12.2.15 releases of Oracle E-Business Suite with Oracle Marketing installed is exposed, particularly if the environment is internet-facing. No public proof of concept exists and the issue is not on CISA's KEV list, so exploitation in the wild is not known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83083 to every E-Business Suite 12.2.3–12.2.15 environment with Oracle Marketing installed. Until patched, restrict internet-facing HTTP access to EBS and review which low-privileged user accounts hold Oracle Marketing responsibilities. Audit Audience/Marketing data access and modification logs for unauthorized read, update, insert, or delete activity.

Affected
Oracle E-Business Suite (Oracle Marketing, component: Audience)12.2.3-12.2.15
Estimated exposure
moderatelikely low thousands of internet-exposed EBS 12.2 instances, only a subset of which run Oracle Marketing — Public internet-wide scans have historically shown on the order of tens of thousands of internet-facing Oracle E-Business Suite servers, and Oracle Marketing is an optional module deployed on only a fraction of EBS environments, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. While the vulnerability is in Oracle Marketing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.