ZeroHour

CVE-2026-83179

moderate

Low-Privilege Data Tampering Flaw in Oracle E-Business Suite Applications Calendar

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83179 is a difficult-to-exploit vulnerability in the Applications Calendar component of Oracle Common Applications Calendar within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A remote attacker with network access via HTTP who already holds a low-privileged account on the EBS instance can trigger the flaw to gain unauthorized ability to create, delete, or modify critical calendar data, read all data accessible to the calendar component, and cause a partial denial of service. Because exploitation requires valid low-privileged credentials and high attack complexity, the risk is concentrated in EBS deployments that expose HTTP endpoints to broad user populations or the internet. Oracle addressed the issue in its Critical Patch Update cycle, and organizations running affected 12.2.x releases should patch. There is no evidence of in-the-wild exploitation and no public proof of concept is known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83179 to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances whose HTTP endpoints are reachable beyond the internal network. Restrict EBS web tier exposure, enforce least-privilege on application accounts, and review calendar module audit and HTTP access logs for anomalous data changes or unauthorized reads by low-privileged users.

Affected
Oracle Common Applications Calendar (Oracle E-Business Suite, component: Applications Calendar)12.2.3 - 12.2.15
Estimated exposure
moderatelikely low-thousands of internet-reachable EBS 12.2.x instances; larger unknown population on internal networks — Public internet scans have historically shown thousands of self-hosted Oracle E-Business Suite web endpoints exposed, and only a subset of those runs the Common Applications Calendar component, so the directly exposed population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data as well as unauthorized access to critical data or complete access to all Oracle Common Applications Calendar accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Applications Calendar. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.