ZeroHour

CVE-2026-83089

moderate

Authenticated Data Tampering Flaw in Oracle Alert for E-Business Suite

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83089 is a high-severity (CVSS 8.1) vulnerability in the Internal Operations component of Oracle Alert, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged, already-authenticated attacker who has network access to the EBS HTTP endpoint, requiring no user interaction. Successful exploitation allows the attacker to create, delete, or modify critical Oracle Alert data and to read all data accessible to Oracle Alert, giving high impact to confidentiality and integrity (no availability impact). Organizations running affected 12.2.x releases with Oracle Alert exposed over HTTP and accessible to low-privilege accounts are at risk. There is no public proof-of-concept and no known in-the-wild exploitation to date, and the flaw is not on the CISA KEV list.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83089 to all E-Business Suite 12.2.3-12.2.15 environments running Oracle Alert. Restrict HTTP access to EBS to trusted networks or VPN rather than exposing it to the open internet, and enforce least-privilege on EBS user accounts. Review audit logs for anomalous activity by low-privileged accounts against Oracle Alert definitions and data.

Affected
Oracle Alert (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderateTens of thousands of E-Business Suite installations worldwide; on the order of 5,000-15,000 internet-exposed instances (estimate) — Oracle EBS is enterprise ERP software deployed by mid-size and large organizations globally, and public internet scans have historically shown roughly 10,000 exposed EBS web endpoints, of which only a subset run the affected 12.2.3-12.2.15…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Alert. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Alert accessible data as well as unauthorized access to critical data or complete access to all Oracle Alert accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.