ZeroHour

CVE-2026-83122

moderate

Authenticated Takeover of Oracle Report Manager in E-Business Suite 12.2 (CVSS 8.8)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83122 is a high-severity flaw in the Internal Operations component of Oracle Report Manager, part of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable over the network via HTTPS by an attacker holding only a low-privileged (authenticated) account, requiring no user interaction. A successful attack lets the attacker fully compromise Oracle Report Manager, with high impact on the confidentiality, integrity, and availability of the component. Because EBS is widely deployed at large enterprises and often internet-facing for partner/self-service access, any 12.2.x environment exposing Report Manager to users beyond trusted internal staff is at risk. No public proof-of-concept exists, the issue is not on CISA's KEV list, and no exploitation in the wild is currently known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83122 to every E-Business Suite environment running 12.2.3-12.2.15. Until patched, restrict HTTPS access to the Report Manager / Internal Operations endpoints to trusted networks (VPN or IP allowlisting) and enforce least-privilege account provisioning. Review logs for anomalous activity by low-privileged accounts against Report Manager to rule out prior exploitation.

Affected
Oracle Report Manager (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderateplausibly ~1,000-10,000 internet-reachable EBS instances, within a total EBS install base likely in the tens of thousands (estimate) — Oracle E-Business Suite is enterprise software deployed by tens of thousands of organizations, and public internet scans (Shodan/Censys) have historically shown a few thousand to low tens of thousands of exposed EBS web endpoints, many of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Report Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.