CVE-2026-83119
largeAuthenticated Takeover Flaw in Oracle E-Business Suite User Management
CVE-2026-83119 is a high-severity (CVSS 8.8) vulnerability in the Internal Operations component of Oracle User Management within Oracle E-Business Suite, affecting releases 12.2.6 through 12.2.15. It is easily exploitable by a low-privileged (valid-credential) attacker with network access via HTTP to the EBS web tier, requiring no user interaction. A successful attack results in complete takeover of the Oracle User Management component, with high impact on confidentiality, integrity, and availability of its data — potentially including unauthorized account provisioning and privilege escalation within the suite. Any organization running an affected E-Business Suite 12.2 release with the Oracle User Management component exposed to users over the network is at risk. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no in-the-wild exploitation is currently known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83119 to all EBS 12.2.6-12.2.15 environments; do not delay patching even though the flaw requires authentication. In the interim, restrict HTTP access to the EBS web tier (VPN/IP allowlisting) and audit low-privilege account activity in User Management/Internal Operations for anomalous provisioning or privilege changes. Verify that no unexplained local users or responsibilities have been created after patching.
| Oracle E-Business Suite (Oracle User Management, Internal Operations component) | 12.2.6-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in takeover of Oracle User Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.