CVE-2026-83134
moderateLow-Privilege Data Disclosure in Oracle iStore Shopping Cart (EBS 12.2.3-12.2.15)
CVE-2026-83134 is a broken access control flaw in the Shopping Cart component of Oracle iStore, part of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP — for example, any registered storefront customer account — can trivially exploit the flaw to read data beyond their authorization, including critical data or all Oracle iStore-accessible data. Because the vulnerability has a scope change (S:C), successful attacks may also expose data belonging to additional Oracle E-Business Suite products beyond iStore itself. Only confidentiality is impacted (no integrity or availability loss), consistent with an information disclosure issue rather than code execution. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild is known as of this analysis.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83134 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running iStore. Until patched, restrict HTTP access to the iStore storefront (VPN/IP allowlisting or WAF rules), enforce least privilege for storefront user accounts, and review iStore and EBS access logs for low-privileged accounts viewing data outside expected scope. Verify whether the iStore Shopping Cart component is actually enabled, since only deployments using it are exposed.
| Oracle iStore (Oracle E-Business Suite, component: Shopping Cart) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. While the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.