ZeroHour

CVE-2026-83328

moderate

High-Privilege Takeover Flaw in Oracle E-Business Suite Applications Framework (Personalization)

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83328 is a vulnerability in the Personalization component of the Oracle Applications Framework within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is exploitable over the network via HTTP by an attacker who already holds high-privileged (administrative-level) access to the EBS environment. Successful exploitation allows the attacker to fully compromise Oracle Applications Framework, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). Because exploitation requires elevated privileges, it primarily enables privilege escalation or persistence by insiders, compromised admin accounts, or attackers who have already breached initial authentication. The flaw is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof of concept is known, so there is no evidence of in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that addresses this CVE to all Oracle E-Business Suite 12.2.3-12.2.15 environments as soon as possible. Audit and minimize accounts with high-privileged EBS responsibilities (especially those able to use Personalization), enforce strong authentication and monitor those accounts for anomalous activity, and verify that EBS is not directly exposed to the internet.

Affected
Oracle Applications Framework (Oracle E-Business Suite, component: Personalization)12.2.3 - 12.2.15
Estimated exposure
moderate≈ thousands of internet-exposed E-Business Suite instances (order of 1,000-10,000), with a broader install base of on-premises enterprise deployments — Oracle E-Business Suite is self-hosted enterprise ERP, and public internet scans (Shodan/Censys) have historically shown a few thousand EBS login endpoints exposed to the internet, while most deployments sit on internal networks; this is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.