ZeroHour

CVE-2026-83177

moderate

Authenticated Data Tampering Flaw in Oracle EBS One-to-One Fulfillment (Documents)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83177 is a high-severity (CVSS 8.1) vulnerability in the Documents component of Oracle One-to-One Fulfillment, a product within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged attacker who has network access to the E-Business Suite over HTTP, with no user interaction required. A successful attack allows the attacker to create, delete, or modify critical One-to-One Fulfillment data and to read all data accessible through that product, giving high impact to both confidentiality and integrity (availability is not affected). Any organization running the affected EBS 12.2.x releases with One-to-One Fulfillment exposed to users or networks is at risk, particularly if the module is reachable from untrusted network zones. No public proof of concept is known and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, so there is no evidence of in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-83177 to all E-Business Suite 12.2.3-12.2.15 environments running One-to-One Fulfillment, and verify the patch on test instances before production rollout. Restrict HTTP access to EBS so the module is not reachable from untrusted networks, and enforce least-privilege roles for accounts that can reach One-to-One Fulfillment. Review audit trails for unexpected document creation, deletion, or modification activity by low-privileged accounts to rule out prior abuse.

Affected
Oracle E-Business Suite One-to-One Fulfillment (Documents component)12.2.3-12.2.15
Estimated exposure
moderatelow thousands of EBS deployments (only the subset licensing/using One-to-One Fulfillment) — Oracle E-Business Suite is deployed at thousands of organizations worldwide with public scans historically showing a few thousand internet-exposed EBS instances, and One-to-One Fulfillment is an optional product covering only a fraction of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle One-to-One Fulfillment accessible data as well as unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.