CVE-2026-83179
moderateLow-Privilege Data Tampering Flaw in Oracle E-Business Suite Applications Calendar
CVE-2026-83179 is a difficult-to-exploit vulnerability in the Applications Calendar component of Oracle Common Applications Calendar within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A remote attacker with network access via HTTP who already holds a low-privileged account on the EBS instance can trigger the flaw to gain unauthorized ability to create, delete, or modify critical calendar data, read all data accessible to the calendar component, and cause a partial denial of service. Because exploitation requires valid low-privileged credentials and high attack complexity, the risk is concentrated in EBS deployments that expose HTTP endpoints to broad user populations or the internet. Oracle addressed the issue in its Critical Patch Update cycle, and organizations running affected 12.2.x releases should patch. There is no evidence of in-the-wild exploitation and no public proof of concept is known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83179 to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances whose HTTP endpoints are reachable beyond the internal network. Restrict EBS web tier exposure, enforce least-privilege on application accounts, and review calendar module audit and HTTP access logs for anomalous data changes or unauthorized reads by low-privileged users.
| Oracle Common Applications Calendar (Oracle E-Business Suite, component: Applications Calendar) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data as well as unauthorized access to critical data or complete access to all Oracle Common Applications Calendar accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Applications Calendar. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.