CVE-2026-83133
moderateUnauthenticated Data Disclosure in Oracle iStore (E-Business Suite) Shopping Cart
CVE-2026-83133 is an easily exploitable vulnerability in the Shopping Cart component of Oracle iStore, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. An unauthenticated remote attacker who can reach the iStore server over HTTP can exploit the flaw without any user interaction or valid credentials. A successful attack results in unauthorized access to critical data or complete access to all Oracle iStore accessible data — the CVSS 3.1 base score is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), indicating a confidentiality-only impact with no integrity or availability effect. Organizations running affected EBS 12.2.x versions with the iStore module exposed to network users, particularly internet-facing B2B/B2C storefronts, are at risk of leaking customer and commerce data. The flaw is not currently listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, but the unauthenticated, low-complexity nature makes it attractive once details circulate.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83133 to all EBS 12.2.3-12.2.15 environments running iStore, and verify the Shopping Cart component is covered. If internet-facing, move the iStore storefront behind a VPN, SSO gateway, or WAF with virtual patching until patches are applied, and restrict HTTP access to the module. Review web server and iStore access logs for unauthenticated requests to shopping cart endpoints that could indicate probing or data extraction.
| Oracle iStore (Oracle E-Business Suite, component: Shopping Cart) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.