ZeroHour

CVE-2026-83186

moderate

Low-Privilege Data Tampering Flaw in Oracle E-Business Suite Calendar

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83186 is an easily exploitable flaw in the Applications Calendar component of Oracle Common Applications Calendar within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A remote attacker with only low-privileged (authenticated) access to the application over HTTP can exploit it to create, delete, or modify critical calendar data or all data accessible to that component, and can cause a partial denial of service. The vulnerability has no confidentiality impact (CVSS 3.1 score 7.1, vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L), so it is primarily a data-integrity and availability risk rather than a data-theft risk. Organizations running the affected 12.2 releases are exposed, particularly if EBS HTTP endpoints are reachable by broad user populations or the internet. No public proof-of-concept or confirmed in-the-wild exploitation has been reported, and the CVE is not on the CISA Known Exploited Vulnerabilities list.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83186 to all E-Business Suite 12.2.3-12.2.15 environments. Restrict HTTP access to EBS to trusted networks/VPN and enforce least-privilege role assignments so low-privileged accounts cannot reach calendar functionality they do not need. Review application audit logs for unexpected calendar record creation, modification, or deletion by low-privilege accounts as a sign of attempted abuse.

Affected
Oracle E-Business Suite (Oracle Common Applications Calendar / Applications Calendar)12.2.3-12.2.15
Estimated exposure
moderate≈ several thousand internet-exposed EBS instances (order of 1k-10k), plus a larger internal-only install base — Oracle E-Business Suite is an on-premises enterprise ERP with an install base commonly estimated in the tens of thousands of organizations, of which public internet scans (e.g., Shodan/FOFA) have historically shown only a few thousand…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Applications Calendar. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.