CVE-2026-83122
moderateAuthenticated Takeover of Oracle Report Manager in E-Business Suite 12.2 (CVSS 8.8)
CVE-2026-83122 is a high-severity flaw in the Internal Operations component of Oracle Report Manager, part of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable over the network via HTTPS by an attacker holding only a low-privileged (authenticated) account, requiring no user interaction. A successful attack lets the attacker fully compromise Oracle Report Manager, with high impact on the confidentiality, integrity, and availability of the component. Because EBS is widely deployed at large enterprises and often internet-facing for partner/self-service access, any 12.2.x environment exposing Report Manager to users beyond trusted internal staff is at risk. No public proof-of-concept exists, the issue is not on CISA's KEV list, and no exploitation in the wild is currently known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83122 to every E-Business Suite environment running 12.2.3-12.2.15. Until patched, restrict HTTPS access to the Report Manager / Internal Operations endpoints to trusted networks (VPN or IP allowlisting) and enforce least-privilege account provisioning. Review logs for anomalous activity by low-privileged accounts against Report Manager to rule out prior exploitation.
| Oracle Report Manager (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Report Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.