CVE-2026-83338
moderateLow-Privilege Takeover Flaw in Oracle E-Business Suite Applications Manager
CVE-2026-83338 is a high-severity vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite, specifically in the Oracle Diagnostics Interfaces component. A remote attacker with only low-privileged credentials and HTTP network access can exploit it to fully compromise Oracle Applications Manager, gaining high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). The flaw affects E-Business Suite releases 12.2.3 through 12.2.15. Because exploitation requires only an authenticated low-privilege account and no user interaction, any EBS environment with exposed self-service or internal HTTP endpoints is at risk if reachable by an attacker with basic credentials. No public proof-of-concept exists and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update that addresses this vulnerability to all E-Business Suite 12.2.3-12.2.15 environments as soon as possible. Restrict network access to Oracle Applications Manager and diagnostics interfaces so they are reachable only from trusted administrative networks, and audit low-privileged EBS accounts for signs of compromise or unusual HTTP activity against diagnostics URLs.
| Oracle E-Business Suite - Oracle Applications Manager (Oracle Diagnostics Interfaces) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.