ZeroHour

CVE-2026-83356

moderate

Broken Access Control Exposes Critical Data in Oracle ECC Framework (EBS) V16

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83356 is an easily exploitable information disclosure vulnerability in the Security component of the Oracle Enterprise Command Center Framework, an add-on framework for Oracle E-Business Suite, affecting supported version V16. A low-privileged (authenticated) attacker with network access via HTTP can trigger the flaw to gain unauthorized read access to critical data, including complete access to all data reachable through the ECC Framework. Because the vulnerability has a scope change (S:C), successful attacks may also expose data from additional E-Business Suite products beyond ECC itself. Only confidentiality is impacted; there is no effect on integrity or availability. The flaw carries a CVSS 3.1 base score of 7.7 (High), and there is no evidence of exploitation in the wild and no public proof of concept.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83356 to the Enterprise Command Center Framework V16 deployment as soon as it is available. Audit ECC user roles and data-access entitlements to confirm low-privilege accounts cannot reach sensitive EBS data through ECC dashboards or APIs, and review access logs for anomalous data reads. Restrict network exposure of ECC/EBS HTTP endpoints to trusted networks or VPN where feasible.

Affected
Oracle Enterprise Command Center Framework (Oracle E-Business Suite)
Estimated exposure
moderatelikely hundreds to low thousands of organizations worldwide (subset of E-Business Suite installs running ECC V16) — Public internet scans have historically shown tens of thousands of internet-facing Oracle E-Business Suite instances, but Enterprise Command Center is an optional component adopted by only a subset of EBS customers, most of them large…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Enterprise Command Center Framework product of Oracle E-Business Suite (component: Security). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Command Center Framework. While the vulnerability is in Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.