ZeroHour

CVE-2026-83129

moderate

Authenticated Data Exposure in Oracle E-Business Suite Sales (Internal Operations)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83129 is an easily exploitable information disclosure flaw in the Internal Operations component of Oracle Sales, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A remote attacker holding a low-privileged account (any legitimate EBS user with minimal rights) can trigger the flaw over HTTP to read data they should not be authorized to see. Because the vulnerability changes scope, a successful attack can result in unauthorized access to critical data or complete access to all Oracle Sales-accessible data, and the impact may spill over into additional products beyond Oracle Sales. Only confidentiality is affected (CVSS 3.1: 7.7, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N); there is no integrity or availability impact. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-83129 to all EBS 12.2.3-12.2.15 environments running Oracle Sales. Until patched, restrict HTTP access to EBS endpoints (especially Internal Operations pages) via network segmentation, VPN, or IP allowlisting, and audit low-privileged accounts for anomalous data-access activity. Review web and application logs for suspicious authenticated requests to the Sales/Internal Operations component as an indicator of attempted exploitation.

Affected
Oracle E-Business Suite (Oracle Sales, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderate≈ a few thousand internet-exposed E-Business Suite instances, subset running Oracle Sales — Oracle EBS is on-premises enterprise software deployed by thousands of organizations worldwide, with public internet scans (Shodan/Censys) typically showing low-thousands of directly exposed EBS web endpoints; only a subset of those run…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. While the vulnerability is in Oracle Sales, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Sales accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.