ZeroHour

CVE-2026-83168

moderate

Authenticated Takeover Flaw in Oracle E-Business Suite Applications Manager

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83168 is a high-severity (CVSS 8.8) vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite, specifically in the Oracle Diagnostics Interfaces component, affecting releases 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTPS can exploit the flaw easily (low attack complexity, no user interaction) to fully compromise Oracle Applications Manager. A successful attack results in a complete takeover of the component, with high impact on the confidentiality, integrity, and availability of the affected system. Any organization running a supported EBS 12.2 release in the affected range and exposing the Applications Manager functionality over HTTPS is at risk. No public proof of concept is known and the flaw is not on the CISA KEV list, so exploitation is currently considered unlikely but plausible against high-value targets.

What to do: Apply the Oracle Critical Patch Update that addresses this CVE to all EBS 12.2.3-12.2.15 environments. Restrict HTTPS access to Applications Manager and diagnostics interfaces so only trusted administrative networks can reach them, and audit EBS logs for anomalous activity by low-privilege accounts against diagnostics endpoints. If patching is delayed, consider temporarily disabling the Oracle Diagnostics Interfaces functionality where feasible.

Affected
Oracle E-Business Suite - Oracle Applications Manager (Oracle Diagnostics Interfaces)12.2.3-12.2.15
Estimated exposure
moderateThousands of organizations / low-thousands of internet-exposed EBS instances — Oracle E-Business Suite is deployed at roughly tens of thousands of enterprises worldwide, with public internet scans (e.g., Shodan/Censys) historically showing on the order of a few thousand exposed EBS web endpoints, most reachable via…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.