ZeroHour

CVE-2026-83125

moderate

Privilege Escalation to Full Takeover in Oracle Report Manager for E-Business Suite

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83125 is a high-severity (CVSS 8.8) vulnerability in the Internal Operations component of Oracle Report Manager, part of Oracle E-Business Suite. A low-privileged attacker — i.e., one holding a valid account with minimal rights — who has network access to the affected system over HTTP can exploit the flaw, which Oracle describes as easily exploitable, to fully compromise Oracle Report Manager with high impact on confidentiality, integrity, and availability. All supported E-Business Suite releases from 12.2.3 through 12.2.15 are affected. Organizations running these versions with Report Manager exposed to networks reachable by low-trust users are at risk of complete component takeover, potentially exposing sensitive financial reporting data. No public proof of concept is known, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83125 to all E-Business Suite instances on 12.2.3-12.2.15. Restrict HTTP access to EBS and Report Manager endpoints via network segmentation and reverse proxies so low-privileged or external users cannot reach the Internal Operations component. Audit low-privilege accounts for suspicious activity targeting Report Manager and verify the component's deployment status on all EBS environments.

Affected
Oracle Report Manager (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderate≈ low-thousands internet-exposed EBS instances; tens of thousands of total EBS installations, subset running Report Manager — Oracle E-Business Suite has an enterprise install base commonly estimated in the tens of thousands of organizations, and public internet scans (Shodan/Censys) have historically shown only a few thousand EBS web endpoints exposed, with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Report Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.