CVE-2026-83117
moderateHigh-Privilege Takeover Flaw in Oracle E-Business Suite Applications DBA (AD Utilities)
CVE-2026-83117 is a vulnerability in the Applications DBA component of Oracle E-Business Suite, specifically within the AD Utilities, affecting releases 12.2.3 through 12.2.15. It is remotely exploitable over HTTP but requires a highly privileged attacker (such as a malicious or compromised administrator-level account), making it best understood as a privilege-escalation and full-compromise path rather than an anonymous remote attack. A successful attack allows the attacker to take over the Applications DBA component, with high impact on confidentiality, integrity, and availability of the E-Business Suite environment (CVSS 3.1 base score 7.2). Any organization running an affected 12.2.x release of Oracle E-Business Suite with the Applications DBA functionality reachable over the network is affected. There is no evidence of in-the-wild exploitation and no public proof of concept is known, but the issue was fixed in Oracle's July 2026 Critical Patch Update cycle.
What to do: Apply the July 2026 Oracle Critical Patch Update for Oracle E-Business Suite to all 12.2.3-12.2.15 environments, prioritizing instances where Applications DBA/AD Utilities endpoints are network-reachable. Restrict HTTP access to administrative EBS functionality to trusted VPN or management networks, and audit privileged Applications DBA accounts for anomalous activity. If patching is delayed, verify that no unpatched admin-facing URLs are internet-exposed.
| Oracle E-Business Suite (Applications DBA, AD Utilities component) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.