CVE-2026-83166
moderatePrivileged Data Disclosure in Oracle E-Business Suite Customer Interaction History
CVE-2026-83166 is a confidentiality-only vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite, specifically the Outcome-Result component, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker with network access over HTTP, requiring no user interaction. Because the vulnerability has a scope change (CVSS S:C), a successful attack can spill beyond Customer Interaction History and significantly impact additional Oracle E-Business Suite products, resulting in unauthorized access to critical data or complete access to all data reachable through Customer Interaction History. Impacts are limited to confidentiality (CVSS 3.1 base 7.7; C:H/I:N/A:N), so integrity and availability are not directly affected. No public proof of concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild is known.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83166 to all Oracle E-Business Suite 12.2.3-12.2.15 environments. Restrict HTTP access to EBS web tiers (self-service/CRM pages) to trusted networks or VPN rather than exposing them to the internet, and enforce least-privilege on internal application accounts since exploitation requires only a low-privileged login. Review audit and access logs around the Customer Interaction History Outcome-Result component for anomalous data retrieval by low-privileged users.
| Oracle Customer Interaction History (Oracle E-Business Suite), component: Outcome-Result | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction History. While the vulnerability is in Oracle Customer Interaction History, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Customer Interaction History accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.