CVE-2026-83187
moderateAuthenticated Data Tampering Flaw in Oracle E-Business Suite Applications Calendar
CVE-2026-83187 is a high-severity (CVSS 7.1) flaw in the Applications Calendar component of Oracle Common Applications Calendar within Oracle E-Business Suite, affecting supported versions 12.2.3 through 12.2.15. A remote attacker with only low-privileged (valid but unprivileged) credentials can exploit it over HTTP with no user interaction or special conditions, making it easily exploitable. A successful attack lets the attacker create, delete, or modify critical data or all data accessible through the Applications Calendar, and read a subset of that data, with high integrity impact and low confidentiality impact. Organizations running affected E-Business Suite 12.2 releases who expose calendar functionality to a broad internal or external user base are at risk. There is no evidence of exploitation in the wild and no public proof of concept, and the issue is not on the CISA KEV list, but it was fixed in Oracle's Critical Patch Update cycle and should be treated as a routine-but-priority patch.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83187 to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances reachable over the network. Restrict HTTP access to EBS so only authenticated, authorized users and trusted networks can reach Applications Calendar pages, and enforce least-privilege account roles. Review calendar records for unexplained creation, deletion, or modification and audit low-privileged accounts for anomalous activity.
| Oracle E-Business Suite - Oracle Common Applications Calendar (Applications Calendar component) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data as well as unauthorized read access to a subset of Oracle Common Applications Calendar accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.