CVE-2026-83159
largeUnauthenticated Local Takeover in Oracle E-Business Suite Applications DBA (ADPatch)
CVE-2026-83159 is a flaw in the ADPatch component of Oracle E-Business Suite's Applications DBA, affecting releases 12.2.3 through 12.2.15. It is exploitable by an unauthenticated attacker who already has operating-system logon access to the server where Applications DBA executes, but a successful attack additionally requires a legitimate person (for example, a DBA performing a patching action) to interact with the system. If those conditions are met, the attacker can fully compromise Applications DBA, with high impact on the confidentiality, integrity, and availability of the E-Business Suite environment — effectively gaining control of the account and schemas that own the applications tier. In practice, this means anyone able to place files on the EBS middleware or database tier combined with an unaware operator represents the realistic threat scenario. The flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof of concept is known, so exploitation activity is believed to be minimal.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83159 to all E-Business Suite 12.2.3-12.2.15 environments. Restrict OS-level logon and file-write access on the applications and database tier hosts to trusted DBA and middleware accounts only, since exploitation requires local foothold plus operator interaction. Review audit logs for unexpected local users, modified patch staging directories, or anomalous adpatch sessions around patching activities.
| Oracle E-Business Suite Applications DBA (component: ADPatch) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.