CVE-2026-83137
moderateAuthenticated takeover flaw in Oracle E-Business Suite Spares Management
CVE-2026-83137 is a high-severity (CVSS 3.1 base score 8.8) vulnerability in the Oracle Spares Management product of Oracle E-Business Suite, specifically in its Internal Operations component. It is easily exploitable by a low-privileged (authenticated) attacker who has network access to the E-Business Suite HTTP endpoint, with no user interaction or special conditions required. A successful attack allows the attacker to fully take over Oracle Spares Management, with high impact on confidentiality, integrity, and availability of the affected software. All supported affected versions are Oracle E-Business Suite 12.2.3 through 12.2.15 running Spares Management. There is no known public proof of concept, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses this vulnerability to all Oracle E-Business Suite 12.2.3-12.2.15 environments running Spares Management. Restrict HTTP access to E-Business Suite so only trusted networks and VPN users can reach it, and enforce least-privilege on application accounts since the flaw requires only a low-privileged session. Review Spares Management activity logs for anomalous actions by low-privileged accounts that could indicate exploitation attempts.
| Oracle Spares Management (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.