ZeroHour

CVE-2026-83169

moderate

Unauthenticated Takeover Flaw in Oracle E-Business Suite One-to-One Fulfillment

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83169 is a difficult-to-exploit, unauthenticated vulnerability in the Java Server Issues component of Oracle One-to-One Fulfillment, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A remote attacker who can reach the affected EBS instance over HTTP — with no credentials or user interaction required — could exploit the flaw to fully compromise the One-to-One Fulfillment component, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). The high attack-complexity rating (AC:H) means successful exploitation is not reliable in practice, likely requiring specific conditions or timing. Organizations running affected EBS 12.2 versions with this module exposed to network traffic, especially internet-facing deployments, are at risk. There is no known public proof of concept, the CVE is not on CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date.

What to do: Apply Oracle's Critical Patch Update that remediates CVE-2026-83169 to all EBS 12.2.3-12.2.15 environments running One-to-One Fulfillment, since 12.2.15 itself is listed as affected and no fixed release train is identified in the advisory. Restrict HTTP access to EBS application tiers so the component is not reachable from untrusted networks, and verify whether the One-to-One Fulfillment module is deployed and licensed. Review access logs and Oracle's advisories for any follow-up indicators of compromise after patching.

Affected
Oracle One-to-One Fulfillment (Oracle E-Business Suite, component: Java Server Issues)12.2.3-12.2.15
Estimated exposure
moderateplausibly thousands of installations (subset of an estimated tens of thousands of on-prem EBS 12.2 deployments that license and use the One-to-One Fulfillment… — Oracle E-Business Suite is on-premises enterprise software with an install base commonly estimated in the tens of thousands of organizations and only a few thousand internet-exposed instances found in public scans; One-to-One Fulfillment…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks of this vulnerability can result in takeover of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.