ZeroHour

CVE-2026-83132

moderate

Authenticated Data Tampering Flaw in Oracle iStore Shopping Cart (EBS 12.2.3-12.2.15)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83132 is a high-severity (CVSS 8.1) vulnerability in the Shopping Cart component of Oracle iStore, an e-commerce module of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A remote attacker with only low-privilege credentials and HTTP access to the iStore application can trigger the flaw, which Oracle describes as easily exploitable with no user interaction required. Successful exploitation lets the attacker create, delete, or modify critical iStore data, and read all data accessible to Oracle iStore, compromising both confidentiality and integrity of storefront data. Any organization running the affected EBS 12.2.3-12.2.15 releases with the iStore module exposed to untrusted networks (especially internet-facing storefronts or accounts available to external customers/partners) is at risk. The flaw is not currently listed in CISA's KEV catalog and no public proof-of-concept is known, suggesting opportunistic rather than active exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83132 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running iStore. Restrict HTTP access to iStore/EBS endpoints so they are not reachable from untrusted networks, and review iStore user accounts and audit logs for suspicious create/delete/modify activity by low-privilege accounts. Enforce least-privilege roles for customer and partner-facing storefront accounts.

Affected
Oracle iStore (Oracle E-Business Suite, component: Shopping Cart)12.2.3-12.2.15
Estimated exposure
moderate≈1,000-10,000 installations (subset of the tens of thousands of organizations running EBS, with only a fraction using the optional iStore module and some of… — Oracle E-Business Suite is deployed at tens of thousands of enterprises globally and internet scans routinely show thousands of exposed EBS web endpoints, but iStore is an optional module adopted by only a subset of those deployments, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.