ZeroHour

CVE-2026-83300

moderate

Authenticated Data Disclosure and Partial DoS in Oracle E-Business Suite XML Gateway

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83300 is a high-severity (CVSS 7.1) vulnerability in the Install component of Oracle XML Gateway, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is exploited over the network via HTTP by an attacker who already holds a low-privileged account on the EBS instance, requiring no user interaction and no special conditions. A successful attack lets the attacker read critical data or all data accessible to Oracle XML Gateway and to cause a partial denial of service of the XML Gateway component; confidentiality and availability are impacted, but integrity is not. Any organization running an affected E-Business Suite 12.2.x release with the XML Gateway component installed is affected, particularly instances with HTTP endpoints reachable by ordinary users or the internet. There is no known public proof of concept and the CVE is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently observed in the wild.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83300 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running Oracle XML Gateway, and confirm the XML Gateway Install component patch was applied. Restrict HTTP access to EBS so only authenticated, necessary users can reach XML Gateway endpoints, and enforce least-privilege for low-privileged accounts since exploitation requires valid credentials. Review audit and access logs for anomalous data access or partial service disruption tied to XML Gateway by low-privileged users.

Affected
Oracle XML Gateway (Oracle E-Business Suite, component: Install)12.2.3-12.2.15
Estimated exposure
moderate≈ several thousand to low tens of thousands of Oracle E-Business Suite 12.2 installations (subset running XML Gateway) — Oracle EBS is enterprise software deployed in the low tens of thousands of organizations worldwide, with internet-wide scans historically showing on the order of 10,000+ exposed EBS web endpoints, of which only a subset runs 12.2 with the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.