ZeroHour

CVE-2026-83165

moderate

Authenticated Takeover Flaw in Oracle E-Business Suite Customer Interaction History

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83165 is a high-severity (CVSS 3.1: 8.8) vulnerability in the User Interface component of Oracle Customer Interaction History, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A remote attacker with only low-privileged (valid but unprivileged) credentials can exploit it over HTTPS with no user interaction, and Oracle rates it as easily exploitable. A successful attack allows the attacker to fully compromise Oracle Customer Interaction History, with high impact on the confidentiality, integrity, and availability of that product's data. Any organization running an affected E-Business Suite 12.2 deployment with the Customer Interaction History product exposed to users is at risk. No public proof-of-concept is known and the flaw is not on the CISA KEV catalog, so there is no indication of widespread in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83165 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running Customer Interaction History, and verify the patch level of the CIH User Interface component. Restrict HTTPS access to EBS to trusted networks/VPN and VPN-gated partner access, and review low-privileged account activity for anomalous access to Customer Interaction History. If immediate patching is not possible, consider disabling or access-restricting the Customer Interaction History responsibility until the patch is applied.

Affected
Oracle Customer Interaction History (Oracle E-Business Suite), component: User Interface12.2.3-12.2.15
Estimated exposure
moderate≈ low thousands of potentially affected E-Business Suite 12.2 deployments (subset running Customer Interaction History) — Oracle E-Business Suite is deployed at mid-to-large enterprises worldwide and internet scans typically show only a few thousand exposed EBS endpoints, with Customer Interaction History being a single optional module, so the truly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Customer Interaction History. Successful attacks of this vulnerability can result in takeover of Oracle Customer Interaction History. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.