ZeroHour

CVE-2026-83090

moderate

Low-Privilege Takeover Flaw in Oracle E-Business Suite Spares Management

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83090 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Internal Operations component of Oracle Spares Management, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A remote attacker who already holds a low-privileged account on the EBS instance can exploit it over HTTP with low complexity, requiring no user interaction, and achieve a complete takeover of Oracle Spares Management with high impacts on confidentiality, integrity, and availability. Any organization running EBS 12.2.3-12.2.15 with the Spares Management product installed and reachable via HTTP is affected, including instances exposed only to authenticated internal or partner users. The flaw is easily exploitable once basic credentials are obtained, but the attack does require an initial low-privileged foothold. There is no known public proof-of-concept and the CVE is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83090 to all EBS 12.2.3-12.2.15 environments running Spares Management, prioritizing instances reachable over HTTP. Restrict network exposure of EBS web endpoints to trusted users and VPNs, and audit low-privileged accounts (including generic or service logins) for suspicious access to Spares Management Internal Operations functions. Review logs for anomalous authenticated activity as a detection signal, since exploitation requires valid low-privilege credentials.

Affected
Oracle Spares Management (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderatelow thousands to low tens of thousands of installations worldwide (EBS 12.2 sites running the Spares Management module) — Oracle E-Business Suite 12.2 is deployed at tens of thousands of enterprises globally, but public internet scans typically show only a few thousand internet-reachable EBS endpoints, and Spares Management is a niche service/spares logistics…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.