CVE-2026-83171
moderateAuthenticated Data Disclosure and Partial DoS in Oracle One-to-One Fulfillment (EBS)
CVE-2026-83171 is a difficult-to-exploit flaw in the Documents component of Oracle One-to-One Fulfillment, a module of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP who already holds valid credentials can trigger the flaw to gain unauthorized read access to critical data or complete access to all data reachable through Oracle One-to-One Fulfillment, and can cause a partial denial of service of the module. Because the vulnerability has a scope change (S:C), successful attacks may also significantly impact additional products beyond the One-to-One Fulfillment module itself. Integrity is not impacted per the CVSS vector, but the combination of high confidentiality impact and scope change yields a CVSS 3.1 base score of 7.1 (high). The vulnerability is not in the CISA KEV catalog, no public proof of concept is known, and there is no indication of in-the-wild exploitation.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83171 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running the One-to-One Fulfillment component. Restrict HTTP access to EBS application tiers (VPNs, allowlists, WAF rules) since exploitation requires a network-accessible low-privilege account, and audit or prune unnecessary low-privilege application accounts. Review logs for unusual document access or availability issues on the One-to-One Fulfillment module, keeping in mind the scope change means adjacent products could be affected in a successful attack.
| Oracle One-to-One Fulfillment (Oracle E-Business Suite, component: Documents) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. While the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.