ZeroHour

CVE-2026-83158

moderate

Local privilege escalation in Oracle Applications Manager RapidClone (EBS 12.2)

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83158 is a vulnerability in the Command Line - RapidClone component of Oracle Applications Manager, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged attacker who already has logon access to the server where Oracle Applications Manager executes, allowing them to elevate their effective access and compromise the Applications Manager. A successful attack yields unauthorized creation, deletion, or modification of critical data, or full read access to all Oracle Applications Manager accessible data, with high confidentiality and integrity impact (CVSS 3.1 base score 7.1; no availability impact). Because the attack vector is local (AV:L), remote exploitation is not indicated — the risk is concentrated on EBS middleware/database hosts reachable by low-privileged OS or application accounts. No public proof of concept is known, the flaw is not on the CISA KEV list, and there is no indication of in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83158 to all EBS 12.2.3-12.2.15 environments. Restrict and audit OS-level logon accounts on EBS application and database tiers, enforcing least privilege so ordinary users cannot reach the RapidClone/Applications Manager command-line tools. Review local account activity on EBS hosts for any unauthorized data modification or access to Applications Manager data.

Affected
Oracle Applications Manager (Oracle E-Business Suite), component: Command Line - RapidClone12.2.3 - 12.2.15
Estimated exposure
moderatelikely low thousands to tens of thousands of on-premises EBS 12.2 installations worldwide (clearly an estimate) — Oracle E-Business Suite is on-premises enterprise software commonly estimated in the tens of thousands of deployments globally, and 12.2.x is the currently supported release line, but the local attack vector means only hosts with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Applications Manager executes to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.