ZeroHour

CVE-2026-83116

moderate

Authenticated data exposure flaw in Oracle E-Business Suite Order Management (Product Diagnostic Tools)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83116 is a high-severity (CVSS 3.1: 7.7) vulnerability in the Product Diagnostic Tools component of Oracle Order Management, part of Oracle E-Business Suite releases 12.2.5 through 12.2.15. A low-privileged attacker with network access via HTTP — for example, any authenticated EBS user such as a self-service or read-only account — can easily trigger the flaw without user interaction. Because the vulnerability exhibits a scope change (S:C), successful attacks can significantly impact products beyond Oracle Order Management itself, and can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data; the impact is confidentiality-only (no integrity or availability impact). Organizations running EBS 12.2 with the Order Management module exposed to broad user populations or untrusted networks are the most at risk. The issue is not on the CISA Known Exploited Vulnerabilities list and no public proof-of-concept is known, suggesting exploitation in the wild is unlikely at this time.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83116 to all EBS 12.2 environments running Order Management 12.2.5-12.2.15. Restrict HTTP access to the EBS application tier (VPN, allow-listing, WAF rules) and minimize the number of low-privileged self-service accounts that can reach the Product Diagnostic Tools functionality. Review application and diagnostic-tool access logs for unusual data retrieval by low-privilege accounts, and verify the patch level of any EBS instance currently internet-exposed.

Affected
Oracle Order Management (Oracle E-Business Suite), component: Product Diagnostic Tools12.2.5 - 12.2.15
Estimated exposure
moderate≈ low thousands of internet-exposed EBS instances; Order Management is deployed in a large share of EBS environments — Public internet scans (e.g., Shodan/Censys) have historically shown a few thousand internet-facing Oracle E-Business Suite endpoints, and Oracle's total EBS customer base is estimated in the low tens of thousands of organizations, most of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.