CVE-2026-83186
moderateLow-Privilege Data Tampering Flaw in Oracle E-Business Suite Calendar
CVE-2026-83186 is an easily exploitable flaw in the Applications Calendar component of Oracle Common Applications Calendar within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A remote attacker with only low-privileged (authenticated) access to the application over HTTP can exploit it to create, delete, or modify critical calendar data or all data accessible to that component, and can cause a partial denial of service. The vulnerability has no confidentiality impact (CVSS 3.1 score 7.1, vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L), so it is primarily a data-integrity and availability risk rather than a data-theft risk. Organizations running the affected 12.2 releases are exposed, particularly if EBS HTTP endpoints are reachable by broad user populations or the internet. No public proof-of-concept or confirmed in-the-wild exploitation has been reported, and the CVE is not on the CISA Known Exploited Vulnerabilities list.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83186 to all E-Business Suite 12.2.3-12.2.15 environments. Restrict HTTP access to EBS to trusted networks/VPN and enforce least-privilege role assignments so low-privileged accounts cannot reach calendar functionality they do not need. Review application audit logs for unexpected calendar record creation, modification, or deletion by low-privilege accounts as a sign of attempted abuse.
| Oracle E-Business Suite (Oracle Common Applications Calendar / Applications Calendar) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Applications Calendar. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.