ZeroHour

CVE-2026-83084

moderate

Authenticated Data Exposure in Oracle E-Business Suite Marketing (Audience)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83084 is a vulnerability in the Audience component of Oracle Marketing within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, requiring no user interaction. Successful attacks result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data, and because of a scope change, the impact can extend beyond Oracle Marketing to additional products. The flaw is confidentiality-only (CVSS 3.1: 7.7, C:H/I:N/A:N), so it does not allow modification or denial of service. No public proof of concept is known and the issue is not on the CISA KEV list, so there is no indication of active exploitation.

What to do: Apply the Oracle Critical Patch Update that addresses this issue for Oracle Marketing/Audience on EBS 12.2.3-12.2.15 as soon as it is available for your release track. Until patched, restrict HTTP access to the EBS application tier (VPN/IP allowlisting) and enforce least-privilege self-service accounts, since exploitation requires a low-privileged authenticated session. Review application and database audit logs for unusual data access by marketing/self-service users to rule out prior compromise.

Affected
Oracle E-Business Suite - Oracle Marketing (Audience component)12.2.3-12.2.15
Estimated exposure
moderate≈ low-thousands of internet-exposed E-Business Suite instances; tens of thousands of on-premises deployments overall (estimate) — Oracle E-Business Suite is an on-premises enterprise product deployed at tens of thousands of organizations, with public internet scans historically showing only a few thousand self-service (HTTP-exposed) instances, so the realistically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. While the vulnerability is in Oracle Marketing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.