CVE-2026-83204
moderateAuthenticated Takeover Flaw in Oracle Sourcing (E-Business Suite 12.2.3-12.2.15)
CVE-2026-83204 is a difficult-to-exploit vulnerability in the Internal Operations component of Oracle Sourcing, a module of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is triggered over HTTP by an authenticated attacker holding only low-privileged access to the EBS instance, so it does not expose systems to anonymous internet attackers by itself. A successful attack allows the attacker to fully compromise Oracle Sourcing, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). The high attack complexity means reliable exploitation is non-trivial, and exploitation likely requires chaining with weak account credentials or an existing foothold. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported; it was disclosed and patched by Oracle through its Critical Patch Update process.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83204 to all E-Business Suite 12.2.3-12.2.15 environments running Sourcing, since Oracle patches are cumulative and no workaround is typically offered. Review Sourcing and Internal Operations audit logs for anomalous activity by low-privileged accounts, and audit those accounts for weak or dormant credentials. Restrict HTTP access to EBS self-service and Sourcing URLs via network controls (VPN/IP allow-listing) to shrink the attack surface for authenticated abuse.
| Oracle Sourcing (Oracle E-Business Suite, component: Internal Operations) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sourcing. Successful attacks of this vulnerability can result in takeover of Oracle Sourcing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.