ZeroHour

CVE-2026-83194

moderate

Authenticated Remote Takeover Flaw in Oracle Depot Repair (E-Business Suite 12.2)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

A high-severity vulnerability (CVSS 3.1: 8.8) in the Internal Operations component of Oracle Depot Repair, part of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to fully compromise the Depot Repair module. The flaw is rated easily exploitable: it requires only an authenticated low-privilege account and no user interaction, and successful attacks result in a complete takeover with high impact on confidentiality, integrity, and availability of the affected module. Supported versions 12.2.10 through 12.2.15 are affected, meaning most current Release 12.2 deployments running this module are exposed. The low privilege requirement means compromised or insider credentials for any basic EBS account could be leveraged to pivot into Depot Repair. There is no known public PoC, no confirmed in-the-wild exploitation, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that addresses this CVE for Oracle Depot Repair; all supported versions 12.2.10-12.2.15 are affected, so patch rather than relying on version drift. Until patched, restrict HTTP access to EBS and Depot Repair endpoints via VPN/IP allowlisting and enforce least-privilege on EBS user accounts. Review EBS audit and access logs for anomalous activity by low-privileged accounts against Depot Repair Internal Operations functions.

Affected
Oracle E-Business Suite - Oracle Depot Repair (component: Internal Operations)12.2.10-12.2.15
Estimated exposure
moderate≈1,000-10,000 installations (subset of E-Business Suite deployments running the Depot Repair module) — Oracle E-Business Suite is deployed at tens of thousands of organizations with public scans showing roughly ten thousand internet-exposed EBS instances, but Depot Repair is an optional, specialized module, so the vulnerable population is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of this vulnerability can result in takeover of Oracle Depot Repair. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.