ZeroHour

CVE-2026-83130

moderate

Authenticated Data Tampering Flaw in Oracle Site Hub for E-Business Suite

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83130 is a vulnerability in the Internal Operations component of Oracle Site Hub, part of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit it easily, requiring no user interaction, to compromise Oracle Site Hub. Successful attacks allow unauthorized creation, deletion, or modification of critical data or all Site Hub-accessible data, as well as unauthorized read access to a subset of that data — a high-impact integrity compromise (CVSS 3.1: 7.1, with C:L/I:H/A:N). Any organization running an affected E-Business Suite release with Site Hub deployed is exposed, particularly if the Site Hub endpoints are reachable by low-trust internal or external users. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so exploitation is not currently known to be occurring in the wild.

What to do: Apply Oracle's Critical Patch Update that addresses CVE-2026-83130 to all Oracle Site Hub deployments running versions 12.2.3-12.2.15. Restrict HTTP access to Site Hub endpoints to trusted, authenticated users only, and review low-privileged account activity for suspicious data creation, modification, or deletion. Audit Site Hub data integrity for signs of unauthorized changes made since the vulnerable window opened.

Affected
Oracle Site Hub (Oracle E-Business Suite), component: Internal Operations12.2.3 - 12.2.15
Estimated exposure
moderatelikely thousands of installations (a subset of the roughly tens of thousands of internet-facing Oracle E-Business Suite instances seen in public scans) — Public internet scans (Shodan/Censys) have historically shown on the order of 10,000-20,000 internet-exposed Oracle E-Business Suite servers, and Site Hub — used to manage multi-instance EBS environments — is deployed on only a portion of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Site Hub. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Site Hub accessible data as well as unauthorized read access to a subset of Oracle Site Hub accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.