ZeroHour

CVE-2026-83126

moderate

CSRF-Style Authenticated Data Exposure in Oracle Sales Online (Oracle EBS 12.2)

CVSS 3.1
7.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83126 is a high-severity (CVSS 7.6) flaw in the Internal Operations component of Oracle Sales Online, part of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. A low-privileged authenticated attacker with HTTP network access can easily trigger the flaw, but exploitation requires interaction from a victim other than the attacker — a pattern typical of CSRF-style attacks where a legitimate user is tricked into performing an action. Because of a scope change, a successful attack can significantly impact products beyond Oracle Sales Online itself, and yields unauthorized access to critical data or complete access to all Sales Online accessible data, plus unauthorized update, insert, or delete access to some of that data; availability is not affected. Organizations running the affected E-Business Suite 12.2 releases with Sales Online deployed are at risk. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates this issue; affected versions are 12.2.3-12.2.15, so patch to the fixed release covered by the latest CPU. If patching is delayed, restrict HTTP access to Sales Online/EBS to trusted networks or VPN rather than exposing it to the internet, and audit low-privileged accounts for anomalous data access or unexpected updates. Because exploitation requires victim interaction, remind users not to click unsolicited links or approve unexpected requests while authenticated to EBS.

Affected
Oracle Sales Online (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderateHundreds to low thousands of exposed instances (subset of EBS deployments running Sales Online) — Oracle E-Business Suite is deployed at roughly tens of thousands of enterprises with public scans typically showing only a few thousand internet-reachable EBS endpoints, and Sales Online is a module adopted by only a fraction of those…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Sales Online, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Sales Online accessible data as well as unauthorized update, insert or delete access to some of Oracle Sales Online accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.