ZeroHour

CVE-2026-83118

moderate

Local Privilege Escalation in Oracle E-Business Suite Applications DBA (AD Utilities)

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83118 is a local privilege escalation flaw in the Applications DBA product of Oracle E-Business Suite, specifically in the AD Utilities component. A low-privileged attacker who already has an operating system logon on the server where Applications DBA executes can exploit it easily (no user interaction required) to fully compromise Applications DBA, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). Successful exploitation effectively results in takeover of the Applications DBA function, which administers the EBS database tier and could therefore expose or corrupt the underlying business data. Affected deployments are Oracle E-Business Suite releases 12.2.3 through 12.2.15 running on-premises or in hosted infrastructure where multiple OS accounts share the server. No public proof-of-concept code is known and there is no evidence of in-the-wild exploitation to date.

What to do: Apply the Oracle Critical Patch Update that remediated this flaw to all E-Business Suite 12.2.3-12.2.15 environments and verify AD Utilities is updated on both application and database tiers. Because exploitation requires local OS access, restrict and audit interactive logons on hosts running Applications DBA and enforce least-privilege on service and administrative accounts. Review local account activity and privilege escalation events on EBS servers for signs of abuse in the interim.

Affected
Oracle E-Business Suite (Applications DBA, AD Utilities component)12.2.3 - 12.2.15
Estimated exposure
moderateThousands of E-Business Suite 12.2.x instances (order of a few thousand to low tens of thousands) — clearly an estimate — Oracle publishes no install counts, but EBS is on-premises enterprise software deployed by thousands of organizations worldwide, and public internet scans show only a few thousand internet-reachable EBS login pages, so the at-risk…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.