CVE-2026-83337
largeLocal Privilege Escalation to Full Takeover in Oracle Fusion Middleware Common Libraries and Tools (RDA)
CVE-2026-83337 is an easily exploitable flaw in the Remote Diagnostic Agent component of Oracle Middleware Common Libraries and Tools, which ships with Oracle Fusion Middleware deployments. It is triggered by a low-privileged attacker who already has an operating-system logon on the host where the middleware executes — no user interaction is required. Successful exploitation allows the attacker to fully take over the affected Oracle Middleware Common Libraries and Tools installation, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). The affected versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Because the attack vector is local, the primary risk is on multi-user hosts, shared application servers, or environments where an attacker already has a foothold; the flaw is not listed in the CISA KEV catalog, no public proof of concept is known, and there is no indication of exploitation in the wild.
What to do: Apply the Oracle Critical Patch Update fix for CVE-2026-83337 to every installation running 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0, obtainable via My Oracle Support. Restrict OS-level logon on middleware hosts to trusted administrators and service accounts, since exploitation requires only a low-privileged local account. Audit local users and review logs for unexpected execution of Remote Diagnostic Agent or other diagnostic tooling as a detection signal.
| Oracle Middleware Common Libraries and Tools (Oracle Fusion Middleware), Remote Diagnostic Agent component | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Remote Diagnostic Agent). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Middleware Common Libraries and Tools executes to compromise Oracle Middleware Common Libraries and Tools. Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.