ZeroHour

CVE-2026-83176

moderate

High-Privilege Takeover Flaw in Oracle E-Business Suite Common Applications (CRM User Management)

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83176 is an easily exploitable vulnerability in the CRM User Management Framework component of Oracle Common Applications within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is exploited by an already high-privileged attacker with network access via HTTP, meaning the flaw effectively allows such an account to escalate to full compromise — a complete takeover of Oracle Common Applications with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). Because exploitation requires pre-existing high privileges and no user interaction, the primary risk is abuse or compromise of administrative accounts rather than anonymous internet-wide attacks. Organizations running E-Business Suite 12.2.3-12.2.15 with the CRM User Management Framework deployed are affected. The vulnerability is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is no evidence of in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83176 to every E-Business Suite environment on 12.2.3-12.2.15 as soon as it is available. Restrict HTTP access to EBS application tiers (VPNs, allowlists, WAF rules) and enforce least privilege and MFA for high-privileged EBS accounts, since exploitation requires such access. Review audit logs for unusual activity by privileged CRM User Management Framework accounts to rule out prior abuse.

Affected
Oracle E-Business Suite — Oracle Common Applications (CRM User Management Framework component)12.2.3-12.2.15
Estimated exposure
moderateLikely thousands of internet-reachable EBS instances, with total affected deployments plausibly in the low tens of thousands of organizations… — E-Business Suite 12.2 is widely deployed on-premises in mid-to-large enterprises, and public internet scans have historically surfaced EBS login/application endpoints in the low thousands to tens of thousands, though only the subset…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks of this vulnerability can result in takeover of Oracle Common Applications. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.