CVE-2026-83132
moderateAuthenticated Data Tampering Flaw in Oracle iStore Shopping Cart (EBS 12.2.3-12.2.15)
CVE-2026-83132 is a high-severity (CVSS 8.1) vulnerability in the Shopping Cart component of Oracle iStore, an e-commerce module of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A remote attacker with only low-privilege credentials and HTTP access to the iStore application can trigger the flaw, which Oracle describes as easily exploitable with no user interaction required. Successful exploitation lets the attacker create, delete, or modify critical iStore data, and read all data accessible to Oracle iStore, compromising both confidentiality and integrity of storefront data. Any organization running the affected EBS 12.2.3-12.2.15 releases with the iStore module exposed to untrusted networks (especially internet-facing storefronts or accounts available to external customers/partners) is at risk. The flaw is not currently listed in CISA's KEV catalog and no public proof-of-concept is known, suggesting opportunistic rather than active exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83132 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running iStore. Restrict HTTP access to iStore/EBS endpoints so they are not reachable from untrusted networks, and review iStore user accounts and audit logs for suspicious create/delete/modify activity by low-privilege accounts. Enforce least-privilege roles for customer and partner-facing storefront accounts.
| Oracle iStore (Oracle E-Business Suite, component: Shopping Cart) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.