ZeroHour

CVE-2026-83189

moderate

Low-Privilege Takeover of Oracle EBS User Management via Proxy User Delegation

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83189 is a high-severity (CVSS 8.8) vulnerability in the Oracle User Management product of Oracle E-Business Suite, specifically in the Proxy User Delegation component. An attacker with only a low-privileged account and HTTP network access to the EBS instance can easily exploit the flaw to fully compromise Oracle User Management, gaining high-impact control over confidentiality, integrity, and availability of the component. Any organization running affected EBS releases 12.2.3 through 12.2.15 is exposed, particularly if the suite is reachable over the network by broad user populations. The issue was assigned by Oracle and is addressed through Oracle's Critical Patch Update process. No public proof-of-concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update remediation for CVE-2026-83189 to all E-Business Suite 12.2.3-12.2.15 environments as soon as the corresponding CPU is available. Review proxy user delegation assignments, workflow roles, and audit logs for unexpected delegation grants or privilege changes made by low-privilege accounts. Restrict HTTP access to EBS via network segmentation and VPN, and audit low-privilege accounts for signs of abuse of the User Management self-service functions.

Affected
Oracle User Management (Oracle E-Business Suite, component: Proxy User Delegation)12.2.3 - 12.2.15
Estimated exposure
moderatelikely thousands of deployments (low thousands internet-exposed), affecting an unknown but substantial enterprise user base — Oracle EBS is an on-premises enterprise ERP typically deployed at mid-size and large organizations; public internet scans historically show on the order of a few thousand exposed EBS login endpoints, and the flaw additionally requires only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in takeover of Oracle User Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.