CVE-2026-83165
moderateAuthenticated Takeover Flaw in Oracle E-Business Suite Customer Interaction History
CVE-2026-83165 is a high-severity (CVSS 3.1: 8.8) vulnerability in the User Interface component of Oracle Customer Interaction History, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A remote attacker with only low-privileged (valid but unprivileged) credentials can exploit it over HTTPS with no user interaction, and Oracle rates it as easily exploitable. A successful attack allows the attacker to fully compromise Oracle Customer Interaction History, with high impact on the confidentiality, integrity, and availability of that product's data. Any organization running an affected E-Business Suite 12.2 deployment with the Customer Interaction History product exposed to users is at risk. No public proof-of-concept is known and the flaw is not on the CISA KEV catalog, so there is no indication of widespread in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83165 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running Customer Interaction History, and verify the patch level of the CIH User Interface component. Restrict HTTPS access to EBS to trusted networks/VPN and VPN-gated partner access, and review low-privileged account activity for anomalous access to Customer Interaction History. If immediate patching is not possible, consider disabling or access-restricting the Customer Interaction History responsibility until the patch is applied.
| Oracle Customer Interaction History (Oracle E-Business Suite), component: User Interface | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Customer Interaction History. Successful attacks of this vulnerability can result in takeover of Oracle Customer Interaction History. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.