ZeroHour

CVE-2026-83113

moderate

Authorization Flaw in Oracle E-Business Suite Quality Module (12.2.3-12.2.15)

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

A vulnerability in the Internal Operations component of the Oracle Quality product within Oracle E-Business Suite allows a low-privileged, authenticated attacker with network access via HTTP to compromise Oracle Quality. The flaw is rated easily exploitable (CVSS 3.1 base score 7.1) but requires valid low-level credentials to trigger. Successful exploitation can result in unauthorized access to critical data or complete read access to all Oracle Quality accessible data, as well as unauthorized update, insert, or delete access to some of that data; availability is not impacted. Organizations running E-Business Suite releases 12.2.3 through 12.2.15 with the Oracle Quality module in use are affected. No public proof-of-concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83113 to all E-Business Suite 12.2.3-12.2.15 environments running Oracle Quality. Restrict HTTP access to EBS through VPN or IP allowlisting so only necessary authenticated business users can reach the Quality module, and enforce least-privilege roles for accounts that do. Review Quality module data and audit logs for unexpected reads or modifications performed by low-privileged accounts.

Affected
Oracle E-Business Suite (Oracle Quality, Internal Operations component)12.2.3-12.2.15
Estimated exposure
moderateplausibly low thousands of installations (subset of the larger E-Business Suite install base that licenses the Quality module) — E-Business Suite is deployed by thousands of enterprises worldwide but is typically intranet- or VPN-facing, with public scans historically showing only a few thousand internet-reachable EBS instances, and Oracle Quality is an optional…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Quality accessible data as well as unauthorized update, insert or delete access to some of Oracle Quality accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.