ZeroHour

CVE-2026-83204

moderate

Authenticated Takeover Flaw in Oracle Sourcing (E-Business Suite 12.2.3-12.2.15)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83204 is a difficult-to-exploit vulnerability in the Internal Operations component of Oracle Sourcing, a module of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is triggered over HTTP by an authenticated attacker holding only low-privileged access to the EBS instance, so it does not expose systems to anonymous internet attackers by itself. A successful attack allows the attacker to fully compromise Oracle Sourcing, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). The high attack complexity means reliable exploitation is non-trivial, and exploitation likely requires chaining with weak account credentials or an existing foothold. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported; it was disclosed and patched by Oracle through its Critical Patch Update process.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83204 to all E-Business Suite 12.2.3-12.2.15 environments running Sourcing, since Oracle patches are cumulative and no workaround is typically offered. Review Sourcing and Internal Operations audit logs for anomalous activity by low-privileged accounts, and audit those accounts for weak or dormant credentials. Restrict HTTP access to EBS self-service and Sourcing URLs via network controls (VPN/IP allow-listing) to shrink the attack surface for authenticated abuse.

Affected
Oracle Sourcing (Oracle E-Business Suite, component: Internal Operations)12.2.3 - 12.2.15
Estimated exposure
moderateThousands of deployments; likely low thousands of internet-reachable EBS instances with Sourcing a subset (order of magnitude: 1k-10k systems) — Public internet scans (Shodan/Censys) typically show only a few thousand internet-exposed Oracle E-Business Suite endpoints, Oracle publishes no install counts, and Sourcing is an optional module used by a subset of the enterprise EBS…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sourcing. Successful attacks of this vulnerability can result in takeover of Oracle Sourcing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.