CVE-2026-83090
moderateLow-Privilege Takeover Flaw in Oracle E-Business Suite Spares Management
CVE-2026-83090 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Internal Operations component of Oracle Spares Management, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A remote attacker who already holds a low-privileged account on the EBS instance can exploit it over HTTP with low complexity, requiring no user interaction, and achieve a complete takeover of Oracle Spares Management with high impacts on confidentiality, integrity, and availability. Any organization running EBS 12.2.3-12.2.15 with the Spares Management product installed and reachable via HTTP is affected, including instances exposed only to authenticated internal or partner users. The flaw is easily exploitable once basic credentials are obtained, but the attack does require an initial low-privileged foothold. There is no known public proof-of-concept and the CVE is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83090 to all EBS 12.2.3-12.2.15 environments running Spares Management, prioritizing instances reachable over HTTP. Restrict network exposure of EBS web endpoints to trusted users and VPNs, and audit low-privileged accounts (including generic or service logins) for suspicious access to Spares Management Internal Operations functions. Review logs for anomalous authenticated activity as a detection signal, since exploitation requires valid low-privilege credentials.
| Oracle Spares Management (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.