ZeroHour

CVE-2026-83167

moderate

Unauthenticated Data Disclosure in Oracle E-Business Suite Application Object Library

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83167 is an easily exploitable flaw in the Core component of the Oracle Application Object Library, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. An unauthenticated attacker with network access to the EBS web tier over HTTP can trigger the flaw without any user interaction, and successful attacks result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. The CVSS 3.1 base score is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), meaning the impact is limited to confidentiality — integrity and availability are not affected. Organizations running affected EBS 12.2.x releases with internet-facing or broadly reachable HTTP endpoints are the primary exposure. No public proof-of-concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that delivers the fix for CVE-2026-83167 to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing any instance reachable over HTTP. Verify that EBS web-tier endpoints (/OA_HTML and related Application Object Library URLs) are not exposed to the public internet, and restrict access via VPN or allow-listing where patching must be scheduled. Review HTTP access logs for unauthenticated requests to Application Object Library resources to rule out precursor probing or data access.

Affected
Oracle Application Object Library (Oracle E-Business Suite), component: Core12.2.3-12.2.15
Estimated exposure
moderateroughly low-thousands of internet-exposed EBS instances (order of magnitude: ~1,000-10,000 systems), plus a larger internal-only population — Oracle E-Business Suite is enterprise software whose public scan data (e.g., exposed /OA_HTML web-tier endpoints) typically shows a few thousand internet-facing instances, with the majority deployed behind corporate networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.