CVE-2026-83176
moderateHigh-Privilege Takeover Flaw in Oracle E-Business Suite Common Applications (CRM User Management)
CVE-2026-83176 is an easily exploitable vulnerability in the CRM User Management Framework component of Oracle Common Applications within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is exploited by an already high-privileged attacker with network access via HTTP, meaning the flaw effectively allows such an account to escalate to full compromise — a complete takeover of Oracle Common Applications with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). Because exploitation requires pre-existing high privileges and no user interaction, the primary risk is abuse or compromise of administrative accounts rather than anonymous internet-wide attacks. Organizations running E-Business Suite 12.2.3-12.2.15 with the CRM User Management Framework deployed are affected. The vulnerability is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is no evidence of in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83176 to every E-Business Suite environment on 12.2.3-12.2.15 as soon as it is available. Restrict HTTP access to EBS application tiers (VPNs, allowlists, WAF rules) and enforce least privilege and MFA for high-privileged EBS accounts, since exploitation requires such access. Review audit logs for unusual activity by privileged CRM User Management Framework accounts to rule out prior abuse.
| Oracle E-Business Suite — Oracle Common Applications (CRM User Management Framework component) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks of this vulnerability can result in takeover of Oracle Common Applications. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.