CVE-2026-83178
moderateHigh-Privilege Takeover Flaw in Oracle E-Business Suite Application Object Library
CVE-2026-83178 is a vulnerability in the Core component of the Oracle Application Object Library within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is exploited over the network via HTTP by an attacker who already holds high privileges, and is rated difficult to exploit (CVSS 3.1: 8.0, AV:N/AC:H/PR:H/S:C with high confidentiality, integrity, and availability impact). A successful attack allows the attacker to fully compromise Oracle Application Object Library, and because the vulnerability changes scope, successful attacks may also significantly impact additional products beyond the vulnerable component. Affected organizations are those running on-premises Oracle E-Business Suite 12.2.3-12.2.15, particularly instances where the HTTP endpoints are reachable by users or service accounts with elevated privileges. No public proof-of-concept exists, the flaw is not on the CISA KEV catalog, and no exploitation in the wild is currently known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83178 to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing 12.2.15 deployments, and verify the patch level of the Application Object Library Core component. Restrict HTTP access to EBS so that only necessary users and networks can reach it, and tightly control and audit high-privilege accounts, since exploitation requires elevated privileges. Review access and application logs for anomalous privileged activity over HTTP as a detection measure.
| Oracle Application Object Library (Oracle E-Business Suite, component: Core) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.