CVE-2026-83167
moderateUnauthenticated Data Disclosure in Oracle E-Business Suite Application Object Library
CVE-2026-83167 is an easily exploitable flaw in the Core component of the Oracle Application Object Library, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. An unauthenticated attacker with network access to the EBS web tier over HTTP can trigger the flaw without any user interaction, and successful attacks result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. The CVSS 3.1 base score is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), meaning the impact is limited to confidentiality — integrity and availability are not affected. Organizations running affected EBS 12.2.x releases with internet-facing or broadly reachable HTTP endpoints are the primary exposure. No public proof-of-concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update that delivers the fix for CVE-2026-83167 to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing any instance reachable over HTTP. Verify that EBS web-tier endpoints (/OA_HTML and related Application Object Library URLs) are not exposed to the public internet, and restrict access via VPN or allow-listing where patching must be scheduled. Review HTTP access logs for unauthenticated requests to Application Object Library resources to rule out precursor probing or data access.
| Oracle Application Object Library (Oracle E-Business Suite), component: Core | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.