CVE-2026-83356
moderateBroken Access Control Exposes Critical Data in Oracle ECC Framework (EBS) V16
CVE-2026-83356 is an easily exploitable information disclosure vulnerability in the Security component of the Oracle Enterprise Command Center Framework, an add-on framework for Oracle E-Business Suite, affecting supported version V16. A low-privileged (authenticated) attacker with network access via HTTP can trigger the flaw to gain unauthorized read access to critical data, including complete access to all data reachable through the ECC Framework. Because the vulnerability has a scope change (S:C), successful attacks may also expose data from additional E-Business Suite products beyond ECC itself. Only confidentiality is impacted; there is no effect on integrity or availability. The flaw carries a CVSS 3.1 base score of 7.7 (High), and there is no evidence of exploitation in the wild and no public proof of concept.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83356 to the Enterprise Command Center Framework V16 deployment as soon as it is available. Audit ECC user roles and data-access entitlements to confirm low-privilege accounts cannot reach sensitive EBS data through ECC dashboards or APIs, and review access logs for anomalous data reads. Restrict network exposure of ECC/EBS HTTP endpoints to trusted networks or VPN where feasible.
| Oracle Enterprise Command Center Framework (Oracle E-Business Suite) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Enterprise Command Center Framework product of Oracle E-Business Suite (component: Security). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Command Center Framework. While the vulnerability is in Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.