CVE-2026-83112
nichePrivileged HTTP takeover flaw in Oracle Lease and Finance Management (EBS)
CVE-2026-83112 is a high-severity (CVSS 7.2) vulnerability in the Internal Operations component of Oracle Lease and Finance Management, a module of Oracle E-Business Suite, affecting versions 12.2.7 through 12.2.15. It is easily exploitable by a high-privileged attacker who has network access to the EBS HTTP endpoint, and a successful attack can result in a complete takeover of Oracle Lease and Finance Management with high impact on confidentiality, integrity, and availability. In practice, this means a compromised or malicious privileged account (such as an applications DBA or module administrator) could pivot to fully compromise the leasing module and its data. Organizations running EBS 12.2 with the Lease and Finance Management module in the affected version range are exposed, particularly where EBS web tiers are reachable beyond tightly controlled internal networks. No public proof-of-concept exists and the CVE is not on the CISA KEV list, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83112 to all EBS 12.2.7-12.2.15 environments running Lease and Finance Management. Restrict HTTP access to EBS application tiers to trusted VPN/internal networks and enforce least privilege on accounts with access to the module's Internal Operations functions. Review audit logs for anomalous activity by high-privileged accounts against the leasing module and rotate those credentials as a precaution.
| Oracle Lease and Finance Management (Oracle E-Business Suite, component: Internal Operations) | 12.2.7-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in takeover of Oracle Lease and Finance Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.