ZeroHour

CVE-2026-83329

moderate

Low-Privilege Takeover Flaw in Oracle E-Business Suite Applications Framework (OAF)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83329 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Personalization component of the Oracle Applications Framework (OAF) within Oracle E-Business Suite, affecting releases 12.2.9 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker who has network access to the EBS web tier via HTTP, requiring no user interaction. A successful attack allows the attacker to compromise Oracle Applications Framework entirely, with high impact on confidentiality, integrity, and availability — effectively a takeover of the framework layer of the EBS instance. Organizations running the affected 12.2.x releases with web-facing or broadly reachable HTTP endpoints are most at risk. The flaw is not currently listed in CISA's KEV catalog and no public proof-of-concept is known, so there is no evidence of in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-83329 to all EBS 12.2.9-12.2.15 environments, prioritizing instances reachable over HTTP. Restrict external access to EBS web tiers (VPN/IP allowlisting) and require strong authentication for low-privileged self-service accounts. Review OAF Personalization definitions and audit logs for unauthorized modifications or suspicious activity by low-privilege users.

Affected
Oracle E-Business Suite / Oracle Applications Framework (OAF), component: Personalization12.2.9 - 12.2.15
Estimated exposure
moderate≈ several thousand internet-exposed EBS instances; total on-prem enterprise deployments plausibly in the tens of thousands — Oracle EBS is on-premises enterprise software, and public internet scan data (e.g., Shodan/Censys) has historically shown only a few thousand EBS web-tier endpoints directly exposed, with the remainder behind VPNs and internal networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.