ZeroHour

CVE-2026-83205

moderate

Authenticated Takeover via Personalization in Oracle E-Business Suite 12.2

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

The Personalization component of Oracle Applications Framework in Oracle E-Business Suite contains an easily exploitable vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the framework. Successful attacks result in complete takeover of Oracle Applications Framework, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). All supported releases of Oracle E-Business Suite 12.2 from 12.2.3 through 12.2.15 are affected. No public proof-of-concept code exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported, but the low privilege requirement means any valid low-level account is sufficient to attempt exploitation.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83205 to all Oracle Applications Framework instances running E-Business Suite 12.2.3–12.2.15, referencing My Oracle Support for the specific patch. Restrict HTTP access to EBS application tiers using a VPN, reverse proxy, or IP allow-listing to reduce internet-facing exposure. Review audit and access logs for anomalous activity by low-privileged accounts targeting personalization functionality.

Affected
Oracle E-Business Suite (Oracle Applications Framework, Personalization component)12.2.3 - 12.2.15
Estimated exposure
moderate≈5,000–15,000 internet-exposed EBS instances, plus a larger internal-only install base (order of 10^4 organizations) — Public internet scans (Shodan/Censys) have historically shown low-four- to low-five-figure counts of internet-facing Oracle E-Business Suite servers, while the majority of EBS deployments sit on internal corporate networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.