CVE-2026-83185
moderateUser-Interaction Data Access Flaw in Oracle E-Business Suite Common Applications
CVE-2026-83185 is a high-severity (CVSS 7.3) vulnerability in the CRM User Management Framework component of Oracle Common Applications within Oracle E-Business Suite, affecting supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit the flaw, but successful attacks require human interaction from a person other than the attacker — a pattern consistent with request-forgery/social-engineering style exploitation where a victim is tricked into performing an action. A successful attack allows the attacker to create, delete, or modify critical data (or all Oracle Common Applications accessible data) and to gain unauthorized read access to critical data or complete access to all accessible data, with no availability impact. Organizations running E-Business Suite 12.2 with the CRM User Management Framework exposed to users over HTTP/HTTPS are affected. No public proof of concept is known and the flaw is not on CISA's KEV list, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update (CPU) that remediates CVE-2026-83185 to all E-Business Suite 12.2.3-12.2.15 environments; do not delay patching waiting for a version upgrade since the fix ships via CPU. Reduce exposure by ensuring EBS HTTP endpoints are not internet-facing and are reachable only through VPN or authenticated reverse proxies. Review audit logs around CRM User Management Framework activity for unexpected data creation, modification, or deletion and for access by low-privilege accounts outside normal behavior.
| Oracle E-Business Suite — Oracle Common Applications (CRM User Management Framework) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications accessible data as well as unauthorized access to critical data or complete access to all Oracle Common Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.