CVE-2026-83127
nicheAuthenticated Data Exposure in Oracle E-Business Suite Sales Offline (12.2.3-12.2.15)
CVE-2026-83127 is a high-severity (CVSS 3.1: 7.7) information disclosure flaw in the Internal Operations component of Oracle Sales Offline, part of Oracle E-Business Suite. A low-privileged attacker with a valid account and HTTP network access to the E-Business Suite instance can exploit the flaw easily, without user interaction, to gain unauthorized access to critical data or complete access to all data reachable through Oracle Sales Offline. Because the CVSS scope is 'changed,' successful attacks may also significantly impact products beyond the Sales Offline component itself. Organizations running Oracle E-Business Suite versions 12.2.3 through 12.2.15 with the Sales Offline product deployed are affected; the flaw has no integrity or availability impact. No public proof-of-concept exists, the CVE is not in CISA's KEV catalog, and no exploitation in the wild has been reported as of this analysis.
What to do: Apply the Oracle Critical Patch Update that delivers the fix for Oracle Sales Offline, since affected versions span 12.2.3 through 12.2.15 and no fixed version number is specified beyond the CPU. Restrict HTTP access to E-Business Suite and the Sales Offline module to trusted networks and authenticated users, and enforce least-privilege roles to limit the low-privileged accounts that could trigger the flaw. Review access logs for low-privilege accounts making unusual requests to Sales Offline Internal Operations endpoints, and verify whether additional E-Business Suite data was exposed given the scope-change impact.
| Oracle E-Business Suite Sales Offline (component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. While the vulnerability is in Oracle Sales Offline, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.