CVE-2026-83300
moderateAuthenticated Data Disclosure and Partial DoS in Oracle E-Business Suite XML Gateway
CVE-2026-83300 is a high-severity (CVSS 7.1) vulnerability in the Install component of Oracle XML Gateway, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is exploited over the network via HTTP by an attacker who already holds a low-privileged account on the EBS instance, requiring no user interaction and no special conditions. A successful attack lets the attacker read critical data or all data accessible to Oracle XML Gateway and to cause a partial denial of service of the XML Gateway component; confidentiality and availability are impacted, but integrity is not. Any organization running an affected E-Business Suite 12.2.x release with the XML Gateway component installed is affected, particularly instances with HTTP endpoints reachable by ordinary users or the internet. There is no known public proof of concept and the CVE is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently observed in the wild.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83300 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running Oracle XML Gateway, and confirm the XML Gateway Install component patch was applied. Restrict HTTP access to EBS so only authenticated, necessary users can reach XML Gateway endpoints, and enforce least-privilege for low-privileged accounts since exploitation requires valid credentials. Review audit and access logs for anomalous data access or partial service disruption tied to XML Gateway by low-privileged users.
| Oracle XML Gateway (Oracle E-Business Suite, component: Install) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.