ZeroHour

CVE-2026-83119

large

Authenticated Takeover Flaw in Oracle E-Business Suite User Management

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83119 is a high-severity (CVSS 8.8) vulnerability in the Internal Operations component of Oracle User Management within Oracle E-Business Suite, affecting releases 12.2.6 through 12.2.15. It is easily exploitable by a low-privileged (valid-credential) attacker with network access via HTTP to the EBS web tier, requiring no user interaction. A successful attack results in complete takeover of the Oracle User Management component, with high impact on confidentiality, integrity, and availability of its data — potentially including unauthorized account provisioning and privilege escalation within the suite. Any organization running an affected E-Business Suite 12.2 release with the Oracle User Management component exposed to users over the network is at risk. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no in-the-wild exploitation is currently known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83119 to all EBS 12.2.6-12.2.15 environments; do not delay patching even though the flaw requires authentication. In the interim, restrict HTTP access to the EBS web tier (VPN/IP allowlisting) and audit low-privilege account activity in User Management/Internal Operations for anomalous provisioning or privilege changes. Verify that no unexplained local users or responsibilities have been created after patching.

Affected
Oracle E-Business Suite (Oracle User Management, Internal Operations component)12.2.6-12.2.15
Estimated exposure
large≈10,000-20,000 internet-exposed EBS servers, plus a larger internal-only install base — Public internet scans (Shodan/FOFA-style) have historically shown on the order of tens of thousands of internet-reachable Oracle E-Business Suite login pages, and many more deployments sit on internal networks reachable by any…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in takeover of Oracle User Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.