CVE-2026-83331
moderateLow-Privilege Takeover Flaw in Oracle E-Business Suite Applications Framework
CVE-2026-83331 is a vulnerability in the Personalization component of Oracle Applications Framework (OAF), part of Oracle E-Business Suite, affecting releases 12.2.9 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit it easily (low attack complexity, no user interaction required) and fully compromise Oracle Applications Framework, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). In practice, this means any authenticated EBS user with minimal privileges on an affected installation could escalate to effectively taking over the application tier. Organizations running EBS 12.2 in the affected version range are at risk, particularly where application HTTP endpoints are broadly reachable. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update (CPU) remediation for CVE-2026-83331 to all E-Business Suite 12.2.9-12.2.15 environments, per Oracle's advisory. Restrict HTTP access to EBS application tiers to trusted networks or VPN rather than exposing them to the internet, and review audit logs for unusual activity by low-privileged accounts around OAF Personalization functionality. Because exploitation requires only a low-privilege account, also verify account provisioning and disable dormant self-service user accounts.
| Oracle Applications Framework (Oracle E-Business Suite, component: Personalization) | 12.2.9-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.