ZeroHour

CVE-2026-83114

moderate

Authenticated Account-Takeover Flaw in Oracle Quality Module of E-Business Suite 12.2

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83114 is a difficult-to-exploit vulnerability in the Internal Operations component of Oracle Quality, a product within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A remote attacker who already holds a low-privileged account on the E-Business Suite instance can exploit the flaw over HTTP to fully compromise the Oracle Quality product. A successful attack gives the attacker high-impact control over the module's confidentiality, integrity, and availability — effectively a takeover of the application. Only organizations running Oracle E-Business Suite 12.2.3-12.2.15 with the Oracle Quality module licensed and deployed are exposed, and exploitation requires valid (low-level) credentials plus network reachability of the HTTP endpoints. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that delivers the fix for CVE-2026-83114 to Oracle Quality on EBS 12.2.3-12.2.15, and verify the patch is applied to every affected environment. Restrict network access to E-Business Suite HTTP endpoints (VPN/IP allow-listing) and review low-privileged EBS accounts for unnecessary access to the Quality module. Monitor authentication and application logs for anomalous activity by low-privilege accounts against Oracle Quality Internal Operations pages.

Affected
Oracle Quality (Oracle E-Business Suite), component: Internal Operations12.2.3-12.2.15
Estimated exposure
moderate≈ low thousands of internet-facing E-Business Suite instances; roughly 10,000 organizations run EBS (clearly an estimate) — Public scan services (Shodan/Censys) typically show on the order of 1,000-5,000 internet-reachable Oracle E-Business Suite login endpoints, and Oracle's EBS installed base is commonly estimated in the low tens of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.