ZeroHour

CVE-2026-83188

moderate

Privileged Attacker Takeover Flaw in Oracle Depot Repair for E-Business Suite 12.2

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83188 is a vulnerability in the Internal Operations component of Oracle Depot Repair, a product within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is exploited over the network via HTTP by an attacker who already holds high privileges in the environment, and successful attacks allow a complete takeover of Oracle Depot Repair with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). In practice this is an escalation/pivot issue: a compromised or malicious privileged account (for example an internal operator or admin) can abuse the flaw to seize full control of the Depot Repair application, moving laterally within E-Business Suite data and workflows. Organizations running Oracle E-Business Suite 12.2.3-12.2.15 with the Depot Repair module licensed or installed are affected. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported as of this analysis.

What to do: Apply the Oracle Critical Patch Update that delivers the fix for CVE-2026-83188 to Oracle Depot Repair on all E-Business Suite 12.2.3-12.2.15 environments, and verify none of your instances remain in the affected range. Restrict HTTP access to EBS/Depot Repair endpoints so only trusted networks and VPN users can reach them, and enforce least-privilege for the high-privilege accounts that could exploit this flaw. Review audit logs for unusual activity by privileged internal-operations accounts on Depot Repair.

Affected
Oracle E-Business Suite Depot Repair (component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderatelow thousands of internet-reachable E-Business Suite instances globally; only a subset runs the Depot Repair module, plus additional internal-only deployments — Public internet scans (e.g., Shodan/Censys) typically show on the order of a few thousand exposed Oracle E-Business Suite login endpoints worldwide, and Depot Repair is a niche service-and-repair module within EBS, most deployments of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of this vulnerability can result in takeover of Oracle Depot Repair. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.