ZeroHour

CVE-2026-83141

moderate

Authenticated Data Exposure in Oracle E-Business Suite Field Service (Internal Operations)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83141 is a vulnerability in the Internal Operations component of Oracle Field Service, part of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged attacker who has network access to the E-Business Suite over HTTP, requiring no user interaction. Because of a scope change, a successful attack can impact resources beyond Oracle Field Service itself and can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data, though integrity and availability are not affected (CVSS 3.1 base score 7.7, confidentiality-focused). Organizations running affected versions of E-Business Suite with the Field Service module exposed to users over the network are at risk, particularly if low-privilege accounts are common. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation is not currently observed.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83141 to E-Business Suite 12.2 environments running 12.2.3–12.2.15, prioritizing systems where the Field Service (Internal Operations) component is enabled. Restrict HTTP access to EBS to trusted networks and VPNs, and audit low-privileged accounts for unexpected access to Field Service data. Review application and database logs around the patch window for evidence of unauthorized data retrieval by low-privilege users.

Affected
Oracle Field Service (Oracle E-Business Suite, component: Internal Operations)12.2.3 - 12.2.15
Estimated exposure
moderatelow thousands of installations, i.e., roughly 1,000–10,000 EBS deployments worldwide — Oracle E-Business Suite is on-premises enterprise software deployed at large organizations globally, public internet scans typically show several thousand internet-reachable EBS endpoints, and only a subset of those run the Field Service…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. While the vulnerability is in Oracle Field Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.