ZeroHour

CVE-2026-83425

moderate

Authenticated Data Exposure and Partial DoS in Oracle CMRO for E-Business Suite

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

An access-control flaw in the Internal Operations component of Oracle Complex Maintenance, Repair and Overhaul (CMRO) lets a low-privileged attacker with network access via HTTP read data beyond their authorization. Successful attacks can result in unauthorized access to critical data or complete access to all CMRO-accessible data, plus a partial denial of service, and because of a scope change the impact can extend to additional products beyond CMRO itself. Deployments affected are Oracle E-Business Suite releases 12.2.12 through 12.2.15 running the CMRO product. No public proof of concept is known and the issue is not on the CISA Known Exploited Vulnerabilities catalog, so there is no confirmed in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83425 and move CMRO to a release later than 12.2.15 (or the corresponding patched bundle). Until patched, restrict HTTP reachability to EBS at the network/WAF layer and tightly audit low-privileged account provisioning, since the flaw only requires a low-privilege authenticated session. Review application and database audit logs for anomalous data reads by low-privilege users and for partial denial-of-service symptoms in CMRO.

Affected
Oracle Complex Maintenance, Repair and Overhaul (Oracle E-Business Suite)12.2.12-12.2.15
Estimated exposure
moderateplausibly ~1,000-5,000 installations globally, with only a fraction internet-exposed — Oracle E-Business Suite is deployed at thousands of large enterprises, but CMRO is a specialized maintenance-repair-overhaul module used mainly in aviation/aerospace and defense, so only a small subset of EBS sites run it; no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.