ZeroHour

CVE-2026-83133

moderate

Unauthenticated Data Disclosure in Oracle iStore (E-Business Suite) Shopping Cart

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83133 is an easily exploitable vulnerability in the Shopping Cart component of Oracle iStore, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. An unauthenticated remote attacker who can reach the iStore server over HTTP can exploit the flaw without any user interaction or valid credentials. A successful attack results in unauthorized access to critical data or complete access to all Oracle iStore accessible data — the CVSS 3.1 base score is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), indicating a confidentiality-only impact with no integrity or availability effect. Organizations running affected EBS 12.2.x versions with the iStore module exposed to network users, particularly internet-facing B2B/B2C storefronts, are at risk of leaking customer and commerce data. The flaw is not currently listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, but the unauthenticated, low-complexity nature makes it attractive once details circulate.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83133 to all EBS 12.2.3-12.2.15 environments running iStore, and verify the Shopping Cart component is covered. If internet-facing, move the iStore storefront behind a VPN, SSO gateway, or WAF with virtual patching until patches are applied, and restrict HTTP access to the module. Review web server and iStore access logs for unauthenticated requests to shopping cart endpoints that could indicate probing or data extraction.

Affected
Oracle iStore (Oracle E-Business Suite, component: Shopping Cart)12.2.3-12.2.15
Estimated exposure
moderate≈1,000–5,000 potentially exposed iStore deployments (subset of internet-facing E-Business Suite instances) — Public internet scans typically show only a few thousand internet-exposed Oracle E-Business Suite instances worldwide, and iStore is an optional e-commerce storefront module used by only a subset of those deployments, most of which sit…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.