CVE-2026-83352
moderateAuthenticated Data Exposure and Partial DoS in Oracle E-Business Suite XML Gateway
CVE-2026-83352 is a high-severity (CVSS 7.1) flaw in the Install component of Oracle XML Gateway, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker who has network access to the EBS instance over HTTP. A successful attack lets the attacker read critical data or all data accessible through Oracle XML Gateway, and to cause a partial denial of service of the XML Gateway component; integrity is not impacted per the CVSS vector. Organizations running affected 12.2.x releases with the XML Gateway component installed and reachable over the network are at risk. The vulnerability is not on the CISA KEV list, no public proof-of-concept is known, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update (CPU) that addresses CVE-2026-83352 to all E-Business Suite 12.2.3-12.2.15 environments running Oracle XML Gateway. Restrict HTTP access to EBS/XML Gateway endpoints to trusted networks or VPN, and review EBS audit and access logs for anomalous activity by low-privilege accounts against XML Gateway. Verify the XML Gateway component is actually installed and patched on each instance, as it may be optional in some deployments.
| Oracle E-Business Suite XML Gateway (component: Install) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.