ZeroHour

CVE-2026-83187

moderate

Authenticated Data Tampering Flaw in Oracle E-Business Suite Applications Calendar

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83187 is a high-severity (CVSS 7.1) flaw in the Applications Calendar component of Oracle Common Applications Calendar within Oracle E-Business Suite, affecting supported versions 12.2.3 through 12.2.15. A remote attacker with only low-privileged (valid but unprivileged) credentials can exploit it over HTTP with no user interaction or special conditions, making it easily exploitable. A successful attack lets the attacker create, delete, or modify critical data or all data accessible through the Applications Calendar, and read a subset of that data, with high integrity impact and low confidentiality impact. Organizations running affected E-Business Suite 12.2 releases who expose calendar functionality to a broad internal or external user base are at risk. There is no evidence of exploitation in the wild and no public proof of concept, and the issue is not on the CISA KEV list, but it was fixed in Oracle's Critical Patch Update cycle and should be treated as a routine-but-priority patch.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83187 to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances reachable over the network. Restrict HTTP access to EBS so only authenticated, authorized users and trusted networks can reach Applications Calendar pages, and enforce least-privilege account roles. Review calendar records for unexplained creation, deletion, or modification and audit low-privileged accounts for anomalous activity.

Affected
Oracle E-Business Suite - Oracle Common Applications Calendar (Applications Calendar component)12.2.3 - 12.2.15
Estimated exposure
moderatelow thousands to ~10,000+ internet-reachable E-Business Suite instances, deployed at thousands of enterprise organizations — Oracle EBS is on-premises enterprise software with an estimated customer base in the low tens of thousands of organizations, and public internet scans have historically shown several thousand exposed EBS login endpoints; exact install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data as well as unauthorized read access to a subset of Oracle Common Applications Calendar accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.