ZeroHour

CVE-2026-83124

moderate

Authenticated Takeover Flaw in Oracle Sales Online, E-Business Suite 12.2.3-12.2.15

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Oracle Sales Online, a CRM module within Oracle E-Business Suite, contains an easily exploitable vulnerability in its Internal Operations component (CVE-2026-83124, CVSS 3.1: 8.8). A remote attacker who already holds a low-privileged account and can reach the E-Business Suite over HTTP can exploit the flaw to fully compromise Oracle Sales Online, with high impact on the confidentiality, integrity, and availability of that product. All supported releases in the 12.2.3-12.2.15 range are affected. Because exploitation only requires a low-privilege account and no user interaction, any internet-facing or broadly reachable EBS deployment running Sales Online is a prime target for lateral abuse by an insider, phished user, or attacker with a stolen credential. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so no active exploitation has been confirmed.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83124 to all E-Business Suite 12.2.3-12.2.15 environments running Sales Online, prioritizing any instance reachable over HTTP from untrusted networks. Restrict HTTP access to EBS via VPN or IP allowlisting so low-privileged web sessions cannot originate from arbitrary sources, and review Sales Online and Internal Operations audit logs for suspicious activity by low-privilege accounts. Verify patch levels across all EBS tiers after the CPU is applied, since supported-version range coverage is broad.

Affected
Oracle Sales Online (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderate≈ low thousands of internet-exposed instances (subset of the ~10,000s of Oracle EBS hosts visible in public scans that run Sales Online) — Public internet scans routinely show on the order of tens of thousands of internet-reachable Oracle E-Business Suite instances, but Sales Online is one optional module within an enterprise self-hosted suite, so only a fraction of those…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. Successful attacks of this vulnerability can result in takeover of Oracle Sales Online. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.