ZeroHour

CVE-2026-83152

moderate

Authenticated Data Manipulation Flaw in Oracle Project Intelligence (EBS 12.2)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83152 is a high-severity (CVSS 8.1) vulnerability in the Internal Operations component of Oracle Project Intelligence, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker who has network access to the EBS instance over HTTP, requiring no user interaction. A successful attack lets the attacker create, delete, or modify critical data — or all Oracle Project Intelligence accessible data — as well as read critical data or gain complete access to all Project Intelligence accessible data; availability is not impacted. Organizations running the affected EBS 12.2 releases with Oracle Project Intelligence deployed are exposed, particularly where the application is reachable over the network by broad user populations. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so exploitation is not known to be occurring in the wild.

What to do: Apply Oracle's Critical Patch Update that remediates CVE-2026-83152 to all EBS 12.2.3-12.2.15 environments running Project Intelligence, and verify the patch is in place on every affected instance. Restrict HTTP/network access to EBS to trusted users and segments, and enforce least-privilege roles so low-privileged accounts cannot reach Project Intelligence functions unnecessarily. Review audit logs for unexpected creation, modification, or deletion of Project Intelligence data by low-privileged accounts to rule out prior exploitation.

Affected
Oracle Project Intelligence (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderatelikely thousands of installations (subset of Oracle EBS 12.2 deployments licensed for Project Intelligence) — Oracle does not publish install counts; E-Business Suite is deployed at an estimated tens of thousands of enterprises globally, but Project Intelligence is a niche product within EBS and public internet scans show only a low thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Intelligence accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Intelligence accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.