ZeroHour

CVE-2026-83170

moderate

Adjacent-Network Takeover Flaw in Oracle EBS One-to-One Fulfillment (Documents)

CVSS 3.1
8.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83170 is a high-severity (CVSS 8.0) vulnerability in the Documents component of Oracle One-to-One Fulfillment, a product within Oracle E-Business Suite. It is exploited by a low-privileged attacker who already has access to the network segment attached to the server running the product, allowing them to fully compromise the One-to-One Fulfillment installation. A successful attack results in complete takeover of the component, with high impact on confidentiality, integrity, and availability. All supported versions from 12.2.3 through 12.2.15 are affected. No public proof of concept is known and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently evidenced.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83170 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running One-to-One Fulfillment. Because exploitation requires adjacent-network access plus a low-privileged account, enforce strict network segmentation around EBS application/database tiers and audit low-privileged EBS user accounts for signs of misuse. Verify that internal monitoring covers the One-to-One Fulfillment Documents component for anomalous activity.

Affected
Oracle One-to-One Fulfillment (Oracle E-Business Suite, component: Documents)12.2.3-12.2.15
Estimated exposure
moderatelow thousands of on-premises Oracle E-Business Suite deployments, with only a subset licensed/running the One-to-One Fulfillment module — Oracle E-Business Suite is on-premises enterprise software with publicly observed internet-exposed instances numbering in the low thousands, and One-to-One Fulfillment is an optional product within EBS, so the truly affected population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle One-to-One Fulfillment executes to compromise Oracle One-to-One Fulfillment. Successful attacks of this vulnerability can result in takeover of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.