CVE-2026-83136
moderateAuthenticated Takeover Flaw in Oracle E-Business Suite Spares Management 12.2
A high-severity (CVSS 8.8) vulnerability in the Internal Operations component of Oracle Spares Management, part of Oracle E-Business Suite, allows a low-privileged authenticated attacker with HTTP network access to fully compromise the Spares Management product. Exploitation is rated as easy (low attack complexity, no user interaction), meaning any valid account with minimal privileges on an affected instance is sufficient. A successful attack results in complete takeover, with high impact on confidentiality, integrity, and availability of the affected module. All E-Business Suite 12.2.3 through 12.2.15 installations running Spares Management are affected. No public proof-of-concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating no known in-the-wild exploitation to date.
What to do: Apply the Oracle Critical Patch Update that addresses this flaw to all E-Business Suite 12.2.3-12.2.15 environments running Spares Management, and verify the Internal Operations component is included in the patch coverage. Restrict HTTP access to EBS via network segmentation or a reverse proxy so the module is not reachable by untrusted networks, and review low-privileged account activity in Spares Management for signs of abuse. Oracle's standard guidance is to apply the latest cumulative CPU rather than individual patches.
| Oracle Spares Management (Oracle E-Business Suite), component: Internal Operations | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.