CVE-2026-83174
moderatePrivilege Escalation to CRM Data in Oracle E-Business Suite 12.2 Technical Foundation
CVE-2026-83174 is a high-severity (CVSS 8.1) authorization flaw in the Application Framework component of Oracle CRM Technical Foundation, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is triggered remotely over HTTP by an attacker who already holds a low-privileged account, such as a self-service or basic employee login, needing no user interaction. A successful exploit lets the attacker create, delete, or modify critical CRM data, or read some or all CRM Technical Foundation data, without affecting availability. Any organization running an affected E-Business Suite 12.2 instance exposed to users over the network is at risk, with internet-facing deployments most exposed. No public proof-of-concept or in-the-wild exploitation is known, and the flaw is not on CISA's KEV list.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83174 to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing any instance reachable over HTTP. Restrict EBS web endpoints to VPN or allow-listed networks and enforce least-privilege roles for low-privilege accounts. Review CRM data audit logs for unauthorized reads, changes, or deletions performed by low-privilege users as an indicator of prior abuse.
| Oracle CRM Technical Foundation (Oracle E-Business Suite, component: Application Framework) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Application Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Technical Foundation accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.