CVE-2026-83118
moderateLocal Privilege Escalation in Oracle E-Business Suite Applications DBA (AD Utilities)
CVE-2026-83118 is a local privilege escalation flaw in the Applications DBA product of Oracle E-Business Suite, specifically in the AD Utilities component. A low-privileged attacker who already has an operating system logon on the server where Applications DBA executes can exploit it easily (no user interaction required) to fully compromise Applications DBA, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). Successful exploitation effectively results in takeover of the Applications DBA function, which administers the EBS database tier and could therefore expose or corrupt the underlying business data. Affected deployments are Oracle E-Business Suite releases 12.2.3 through 12.2.15 running on-premises or in hosted infrastructure where multiple OS accounts share the server. No public proof-of-concept code is known and there is no evidence of in-the-wild exploitation to date.
What to do: Apply the Oracle Critical Patch Update that remediated this flaw to all E-Business Suite 12.2.3-12.2.15 environments and verify AD Utilities is updated on both application and database tiers. Because exploitation requires local OS access, restrict and audit interactive logons on hosts running Applications DBA and enforce least-privilege on service and administrative accounts. Review local account activity and privilege escalation events on EBS servers for signs of abuse in the interim.
| Oracle E-Business Suite (Applications DBA, AD Utilities component) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.