CVE-2026-83128
moderateUnauthenticated Data Exposure in Oracle Sales Offline (E-Business Suite)
CVE-2026-83128 is a vulnerability in the Internal Operations component of Oracle Sales Offline, part of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack results in unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data, with high confidentiality impact but no effect on integrity or availability (CVSS 3.1 base score 7.5). Organizations running affected E-Business Suite releases with the Sales Offline product reachable over the network are exposed. No public proof-of-concept is known and the flaw is not on the CISA KEV list, indicating no observed in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that remediated this issue for Oracle Sales Offline and verify you are on a fixed release of E-Business Suite 12.2. Until patched, restrict HTTP access to Sales Offline Internal Operations endpoints at the network layer (VPN/IP allowlisting) so they are not reachable by unauthenticated internet users. Review access logs for unauthenticated requests to Sales Offline URLs to detect any attempted data theft.
| Oracle Sales Offline (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.