CVE-2026-83125
moderatePrivilege Escalation to Full Takeover in Oracle Report Manager for E-Business Suite
CVE-2026-83125 is a high-severity (CVSS 8.8) vulnerability in the Internal Operations component of Oracle Report Manager, part of Oracle E-Business Suite. A low-privileged attacker — i.e., one holding a valid account with minimal rights — who has network access to the affected system over HTTP can exploit the flaw, which Oracle describes as easily exploitable, to fully compromise Oracle Report Manager with high impact on confidentiality, integrity, and availability. All supported E-Business Suite releases from 12.2.3 through 12.2.15 are affected. Organizations running these versions with Report Manager exposed to networks reachable by low-trust users are at risk of complete component takeover, potentially exposing sensitive financial reporting data. No public proof of concept is known, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83125 to all E-Business Suite instances on 12.2.3-12.2.15. Restrict HTTP access to EBS and Report Manager endpoints via network segmentation and reverse proxies so low-privileged or external users cannot reach the Internal Operations component. Audit low-privilege accounts for suspicious activity targeting Report Manager and verify the component's deployment status on all EBS environments.
| Oracle Report Manager (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Report Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.