ZeroHour

CVE-2026-83121

moderate

Low-Privilege Takeover of Oracle Marketing (E-Business Suite Audience)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83121 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Audience component of Oracle Marketing, part of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is described as easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, meaning any user with even a minimal account on an exposed instance can trigger the flaw. A successful attack allows the attacker to fully compromise Oracle Marketing, with high impact on the confidentiality, integrity, and availability of that component. Organizations running the affected E-Business Suite releases with Oracle Marketing deployed and reachable over the network are exposed, particularly where EBS web endpoints face the internet or a broad internal user base. No public proof of concept is known, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediated this flaw to all E-Business Suite 12.2.3-12.2.15 environments running Oracle Marketing, prioritizing any instance whose web tier is internet-facing. Until patched, restrict HTTP access to EBS to trusted networks/VPN, review accounts with even low-privilege roles for compromise, and audit logs for anomalous activity in the Oracle Marketing/Audience component.

Affected
Oracle Marketing (Oracle E-Business Suite, component: Audience)12.2.3 - 12.2.15
Estimated exposure
moderatethousands of organizations (subset of the estimated low-tens-of-thousands of Oracle E-Business Suite deployments; low thousands of internet-reachable EBS web… — Oracle E-Business Suite is estimated to run at roughly 10,000+ organizations worldwide, public internet scans have historically shown a few thousand exposed EBS HTTP endpoints, and only the subset with the Oracle Marketing/Audience…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in takeover of Oracle Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.