ZeroHour

CVE-2026-83157

moderate

High-Privilege Takeover in Oracle E-Business Suite Applications Manager RapidClone

CVSS 3.1
8.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83157 is a difficult-to-exploit vulnerability in the Command Line - RapidClone component of Oracle Applications Manager, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is triggered over the network via HTTP by an attacker who already holds high privileges, and a successful attack results in a complete takeover of Oracle Applications Manager. Because the vulnerability has a scope change, successful attacks may also significantly impact additional products beyond Applications Manager, with high impacts to confidentiality, integrity, and availability (CVSS 3.1 base score 8.0). Any organization running E-Business Suite 12.2.3-12.2.15 with Applications Manager exposed over HTTP to privileged users is affected. There is no known public proof of concept, it does not appear in the CISA Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83157 to all E-Business Suite 12.2.3-12.2.15 environments as soon as your patching cycle allows. Restrict HTTP access to Oracle Applications Manager and RapidClone command-line functionality to trusted administrative networks and accounts, since exploitation requires high privileges. Review EBS audit and concurrent-manager logs for unexpected RapidClone or cloning activity by privileged accounts, and enforce least-privilege separation for administrators who do not need Applications Manager access.

Affected
Oracle E-Business Suite (Oracle Applications Manager, Command Line - RapidClone component)12.2.3 - 12.2.15
Estimated exposure
moderatelikely a few thousand internet-exposed EBS instances, with a broader internal installed base plausibly in the tens of thousands of deployments — Oracle does not publish installation counts, but public internet scan services (Shodan/Censys) typically show low-thousands of internet-exposed Oracle E-Business Suite instances, and 12.2.x is the dominant long-supported release family, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager. While the vulnerability is in Oracle Applications Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.