CVE-2026-83163
moderateAuthenticated File Upload Flaw in Oracle E-Business Suite Application Object Library
CVE-2026-83163 is a high-severity (CVSS 8.8) vulnerability in the Attachments / File Upload component of the Oracle Application Object Library, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A low-privileged attacker — meaning any holder of a basic valid application account — with network access via HTTP can abuse the file upload/attachment handling to fully compromise the Oracle Application Object Library. A successful attack results in complete takeover, with high impact on confidentiality, integrity, and availability of the affected E-Business Suite component. Oracle rates the flaw as easily exploitable, so any internet-facing or broadly reachable EBS 12.2 deployment with ordinary application users is at material risk. The flaw was fixed in an Oracle Critical Patch Update; there is no known public proof of concept and no confirmed exploitation in the wild as of this analysis.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83163 to all E-Business Suite 12.2.3-12.2.15 environments as a priority. Until patched, restrict HTTP access to EBS application tiers to trusted networks or VPN and place a WAF/reverse proxy in front, since exploitation requires only a low-privileged account. Review attachment upload directories for unexpected or webshell-like files and audit low-privilege application accounts for anomalous upload activity.
| Oracle Application Object Library (Oracle E-Business Suite) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.