ZeroHour

CVE-2026-83131

moderate

Authenticated File Download Flaw Exposes Critical Data in Oracle EBS Web ADI

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

Oracle Web Applications Desktop Integrator (Web ADI), a component of Oracle E-Business Suite, contains an easily exploitable flaw in its File download functionality affecting versions 12.2.3 through 12.2.15. A low-privileged attacker with valid E-Business Suite credentials and network access via HTTPS can trigger the flaw to gain unauthorized access to critical data, potentially including complete access to all data reachable through Web Applications Desktop Integrator. The CVSS 3.1 base score is 7.7 (high) with confidentiality-only impact (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), and the scope-change metric means successful attacks may significantly affect additional Oracle products beyond Web ADI itself. Any organization running Oracle E-Business Suite release 12.2.3-12.2.15 with Web ADI deployed is affected. No public proof of concept exists, the flaw is not on CISA's KEV, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update containing the fix for CVE-2026-83131 to all Oracle E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances reachable from the internet or by broad user populations. Restrict HTTPS access to EBS via VPN or IP allowlisting so low-privileged users cannot reach Web ADI endpoints unnecessarily. Review web server and EBS access logs for anomalous file-download requests by low-privilege accounts to Web ADI endpoints, which would indicate attempted exploitation.

Affected
Oracle Web Applications Desktop Integrator (Oracle E-Business Suite), component: File download12.2.3 - 12.2.15
Estimated exposure
moderateon the order of a few thousand internet-exposed EBS instances out of an estimated 10,000+ Oracle E-Business Suite customer organizations — EBS is an on-premises enterprise ERP with an installed base commonly estimated in the low tens of thousands of organizations, and public internet scans consistently show a few thousand internet-reachable EBS HTTPS endpoints; Web ADI is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Web Applications Desktop Integrator. While the vulnerability is in Oracle Web Applications Desktop Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Web Applications Desktop Integrator accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.