CVE-2026-83124
moderateAuthenticated Takeover Flaw in Oracle Sales Online, E-Business Suite 12.2.3-12.2.15
Oracle Sales Online, a CRM module within Oracle E-Business Suite, contains an easily exploitable vulnerability in its Internal Operations component (CVE-2026-83124, CVSS 3.1: 8.8). A remote attacker who already holds a low-privileged account and can reach the E-Business Suite over HTTP can exploit the flaw to fully compromise Oracle Sales Online, with high impact on the confidentiality, integrity, and availability of that product. All supported releases in the 12.2.3-12.2.15 range are affected. Because exploitation only requires a low-privilege account and no user interaction, any internet-facing or broadly reachable EBS deployment running Sales Online is a prime target for lateral abuse by an insider, phished user, or attacker with a stolen credential. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so no active exploitation has been confirmed.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83124 to all E-Business Suite 12.2.3-12.2.15 environments running Sales Online, prioritizing any instance reachable over HTTP from untrusted networks. Restrict HTTP access to EBS via VPN or IP allowlisting so low-privileged web sessions cannot originate from arbitrary sources, and review Sales Online and Internal Operations audit logs for suspicious activity by low-privilege accounts. Verify patch levels across all EBS tiers after the CPU is applied, since supported-version range coverage is broad.
| Oracle Sales Online (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. Successful attacks of this vulnerability can result in takeover of Oracle Sales Online. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.