CVE-2026-83110
moderateUnauthenticated Data Disclosure in Oracle E-Business Suite Marketing (Audience)
CVE-2026-83110 is an easily exploitable flaw in the Audience component of Oracle Marketing within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. An unauthenticated attacker with network access to the server over HTTP can send requests that compromise Oracle Marketing, resulting in unauthorized access to critical data or complete access to all Oracle Marketing-accessible data. The vulnerability is confidentiality-only (CVSS 3.1 base 7.5: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), so it does not allow modification or denial of service, but the exposed marketing data (e.g., audience/contact information) can be highly sensitive. Organizations running affected E-Business Suite releases with the Oracle Marketing module exposed to network users are at risk, particularly if the web tier is internet-facing. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation is currently considered unlikely but plausible given how trivially the bug can be reached.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83110 to your E-Business Suite 12.2 environment as soon as your patch cycle allows. Until patched, restrict network access to EBS HTTP endpoints (especially the Marketing/Audience servlets) at the firewall or reverse proxy so only trusted users and VPN ranges can reach them. Review HTTP access logs and Marketing data access for anomalous unauthenticated requests to detect any attempted or successful harvesting of audience data.
| Oracle E-Business Suite (Oracle Marketing, Audience component) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.