ZeroHour

CVE-2026-83134

moderate

Low-Privilege Data Disclosure in Oracle iStore Shopping Cart (EBS 12.2.3-12.2.15)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83134 is a broken access control flaw in the Shopping Cart component of Oracle iStore, part of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP — for example, any registered storefront customer account — can trivially exploit the flaw to read data beyond their authorization, including critical data or all Oracle iStore-accessible data. Because the vulnerability has a scope change (S:C), successful attacks may also expose data belonging to additional Oracle E-Business Suite products beyond iStore itself. Only confidentiality is impacted (no integrity or availability loss), consistent with an information disclosure issue rather than code execution. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild is known as of this analysis.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83134 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running iStore. Until patched, restrict HTTP access to the iStore storefront (VPN/IP allowlisting or WAF rules), enforce least privilege for storefront user accounts, and review iStore and EBS access logs for low-privileged accounts viewing data outside expected scope. Verify whether the iStore Shopping Cart component is actually enabled, since only deployments using it are exposed.

Affected
Oracle iStore (Oracle E-Business Suite, component: Shopping Cart)12.2.3-12.2.15
Estimated exposure
moderate≈ low thousands of internet-exposed EBS/iStore storefront endpoints (subset of thousands of EBS installs) — Public internet scan data typically shows only a few thousand internet-reachable Oracle E-Business Suite web endpoints worldwide, and iStore is an optional storefront module used by a subset of those deployments, so the exposed population…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. While the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.