CVE-2026-83131
moderateAuthenticated File Download Flaw Exposes Critical Data in Oracle EBS Web ADI
Oracle Web Applications Desktop Integrator (Web ADI), a component of Oracle E-Business Suite, contains an easily exploitable flaw in its File download functionality affecting versions 12.2.3 through 12.2.15. A low-privileged attacker with valid E-Business Suite credentials and network access via HTTPS can trigger the flaw to gain unauthorized access to critical data, potentially including complete access to all data reachable through Web Applications Desktop Integrator. The CVSS 3.1 base score is 7.7 (high) with confidentiality-only impact (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), and the scope-change metric means successful attacks may significantly affect additional Oracle products beyond Web ADI itself. Any organization running Oracle E-Business Suite release 12.2.3-12.2.15 with Web ADI deployed is affected. No public proof of concept exists, the flaw is not on CISA's KEV, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update containing the fix for CVE-2026-83131 to all Oracle E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances reachable from the internet or by broad user populations. Restrict HTTPS access to EBS via VPN or IP allowlisting so low-privileged users cannot reach Web ADI endpoints unnecessarily. Review web server and EBS access logs for anomalous file-download requests by low-privilege accounts to Web ADI endpoints, which would indicate attempted exploitation.
| Oracle Web Applications Desktop Integrator (Oracle E-Business Suite), component: File download | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Web Applications Desktop Integrator. While the vulnerability is in Oracle Web Applications Desktop Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Web Applications Desktop Integrator accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.