CVE-2026-83329
moderateLow-Privilege Takeover Flaw in Oracle E-Business Suite Applications Framework (OAF)
CVE-2026-83329 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Personalization component of the Oracle Applications Framework (OAF) within Oracle E-Business Suite, affecting releases 12.2.9 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker who has network access to the EBS web tier via HTTP, requiring no user interaction. A successful attack allows the attacker to compromise Oracle Applications Framework entirely, with high impact on confidentiality, integrity, and availability — effectively a takeover of the framework layer of the EBS instance. Organizations running the affected 12.2.x releases with web-facing or broadly reachable HTTP endpoints are most at risk. The flaw is not currently listed in CISA's KEV catalog and no public proof-of-concept is known, so there is no evidence of in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-83329 to all EBS 12.2.9-12.2.15 environments, prioritizing instances reachable over HTTP. Restrict external access to EBS web tiers (VPN/IP allowlisting) and require strong authentication for low-privileged self-service accounts. Review OAF Personalization definitions and audit logs for unauthorized modifications or suspicious activity by low-privilege users.
| Oracle E-Business Suite / Oracle Applications Framework (OAF), component: Personalization | 12.2.9 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.