ZeroHour

CVE-2026-83159

large

Unauthenticated Local Takeover in Oracle E-Business Suite Applications DBA (ADPatch)

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83159 is a flaw in the ADPatch component of Oracle E-Business Suite's Applications DBA, affecting releases 12.2.3 through 12.2.15. It is exploitable by an unauthenticated attacker who already has operating-system logon access to the server where Applications DBA executes, but a successful attack additionally requires a legitimate person (for example, a DBA performing a patching action) to interact with the system. If those conditions are met, the attacker can fully compromise Applications DBA, with high impact on the confidentiality, integrity, and availability of the E-Business Suite environment — effectively gaining control of the account and schemas that own the applications tier. In practice, this means anyone able to place files on the EBS middleware or database tier combined with an unaware operator represents the realistic threat scenario. The flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof of concept is known, so exploitation activity is believed to be minimal.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83159 to all E-Business Suite 12.2.3-12.2.15 environments. Restrict OS-level logon and file-write access on the applications and database tier hosts to trusted DBA and middleware accounts only, since exploitation requires local foothold plus operator interaction. Review audit logs for unexpected local users, modified patch staging directories, or anomalous adpatch sessions around patching activities.

Affected
Oracle E-Business Suite Applications DBA (component: ADPatch)12.2.3 - 12.2.15
Estimated exposure
largeTens of thousands of on-premises Oracle E-Business Suite 12.2.x deployments worldwide (rough estimate) — Oracle E-Business Suite is a widely deployed enterprise ERP with an install base commonly estimated in the tens of thousands of organizations, most running intranet-only 12.2 instances on the affected release line, though exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.