ZeroHour

CVE-2026-83120

large

Privilege Escalation to Full Takeover in Oracle Alert (E-Business Suite 12.2)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83120 is a flaw in the Internal Operations component of Oracle Alert, part of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit it easily (CVSS 3.1: 8.8) to fully compromise the Oracle Alert component, with high impact on confidentiality, integrity, and availability — effectively a takeover. Successful exploitation requires only a valid low-privilege account on the EBS instance, making insiders or any compromised credentials a viable path. Organizations running affected E-Business Suite 12.2 releases that expose the Oracle Alert component are at risk. No public proof-of-concept is known and the flaw is not on the CISA KEV list, so exploitation in the wild is not currently indicated.

What to do: Apply the Oracle Critical Patch Update patch for Oracle Alert on all E-Business Suite 12.2.3-12.2.15 environments, prioritizing internet-reachable instances. Restrict HTTP access to EBS via VPN/IP allow-listing and enforce least-privilege on EBS user accounts since exploitation requires only a low-privileged login. Review Oracle Alert logs and configurations for unauthorized changes or unexpected activity.

Affected
Oracle Alert (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
large≈10,000-20,000 internet-exposed E-Business Suite instances (estimate; only a subset runs Oracle Alert) — Public internet scans (Shodan/FOFA) have historically shown low-tens-of-thousands of internet-facing Oracle EBS deployments, though most EBS instances are intranet-hosted and not all license or use Oracle Alert.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Alert. Successful attacks of this vulnerability can result in takeover of Oracle Alert. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.