ZeroHour

CVE-2026-83206

niche

Low-Privilege Takeover Flaw in Oracle Banking Corporate Lending Process Management

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83206 is a difficult-to-exploit vulnerability in the Base component of Oracle Banking Corporate Lending Process Management (part of Oracle Financial Services Applications), affecting supported versions 14.5.0.0.0 through 14.9.0.0.0. A low-privileged attacker with network access via HTTP can trigger the flaw, but a successful attack requires human interaction from a person other than the attacker, meaning the attacker must first persuade another user (e.g., an authorized banking staff member) to take some action. If exploited, the attack can result in a full takeover of the Oracle Banking Corporate Lending Process Management installation, with high impact on the confidentiality, integrity, and availability of the application (CVSS 3.1 base score 7.1). Organizations running the affected 14.5–14.9 releases, typically banks and financial institutions using Oracle's corporate lending platform, are affected. No public proof-of-concept exists, the flaw is not on CISA's Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83206 to all supported releases of Oracle Banking Corporate Lending Process Management in the 14.5–14.9 range. Because exploitation requires a low-privilege account plus user interaction, review application logs for anomalous activity by low-privileged users and reinforce phishing/social-engineering awareness for staff with access to the platform. Restrict network-level access to the application so only authenticated banking operations users can reach it over HTTP.

Affected
Oracle Banking Corporate Lending Process Management (Oracle Financial Services Applications)14.5.0.0.0-14.9.0.0.0
Estimated exposure
nichelikely dozens to low hundreds of financial-institution deployments worldwide (exact count unknown) — This is licensed enterprise banking software deployed per institution, usually on internal networks rather than exposed to the internet, and no public active-install counts or internet-scan data exist for it, so exposure is necessarily…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.