CVE-2026-83189
moderateLow-Privilege Takeover of Oracle EBS User Management via Proxy User Delegation
CVE-2026-83189 is a high-severity (CVSS 8.8) vulnerability in the Oracle User Management product of Oracle E-Business Suite, specifically in the Proxy User Delegation component. An attacker with only a low-privileged account and HTTP network access to the EBS instance can easily exploit the flaw to fully compromise Oracle User Management, gaining high-impact control over confidentiality, integrity, and availability of the component. Any organization running affected EBS releases 12.2.3 through 12.2.15 is exposed, particularly if the suite is reachable over the network by broad user populations. The issue was assigned by Oracle and is addressed through Oracle's Critical Patch Update process. No public proof-of-concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update remediation for CVE-2026-83189 to all E-Business Suite 12.2.3-12.2.15 environments as soon as the corresponding CPU is available. Review proxy user delegation assignments, workflow roles, and audit logs for unexpected delegation grants or privilege changes made by low-privilege accounts. Restrict HTTP access to EBS via network segmentation and VPN, and audit low-privilege accounts for signs of abuse of the User Management self-service functions.
| Oracle User Management (Oracle E-Business Suite, component: Proxy User Delegation) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in takeover of Oracle User Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.