CVE-2026-83089
moderateAuthenticated Data Tampering Flaw in Oracle Alert for E-Business Suite
CVE-2026-83089 is a high-severity (CVSS 8.1) vulnerability in the Internal Operations component of Oracle Alert, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged, already-authenticated attacker who has network access to the EBS HTTP endpoint, requiring no user interaction. Successful exploitation allows the attacker to create, delete, or modify critical Oracle Alert data and to read all data accessible to Oracle Alert, giving high impact to confidentiality and integrity (no availability impact). Organizations running affected 12.2.x releases with Oracle Alert exposed over HTTP and accessible to low-privilege accounts are at risk. There is no public proof-of-concept and no known in-the-wild exploitation to date, and the flaw is not on the CISA KEV list.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83089 to all E-Business Suite 12.2.3-12.2.15 environments running Oracle Alert. Restrict HTTP access to EBS to trusted networks or VPN rather than exposing it to the open internet, and enforce least-privilege on EBS user accounts. Review audit logs for anomalous activity by low-privileged accounts against Oracle Alert definitions and data.
| Oracle Alert (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Alert. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Alert accessible data as well as unauthorized access to critical data or complete access to all Oracle Alert accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.