ZeroHour

CVE-2026-83430

moderate

Low-Privilege Data Manipulation Flaw in Oracle Product Workbench (E-Business Suite 12.2)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83430 is an easily exploitable authorization weakness in the Internal Operations component of Oracle Product Workbench, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A remote attacker with network access via HTTP who already holds a low-privileged account on the E-Business Suite instance can exploit it to gain unauthorized creation, deletion, or modification rights over critical Product Workbench data, as well as unauthorized read access to that data. The flaw carries a CVSS 3.1 base score of 8.1 (high), with high confidentiality and integrity impact but no availability impact, and it requires no user interaction. Organizations running affected 12.2.x releases of E-Business Suite are exposed, particularly those whose application tiers are reachable over the network. No public proof-of-concept exists and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed in the wild.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83430 to all E-Business Suite 12.2.3–12.2.15 environments, and prioritize any instance whose HTTP endpoints are reachable beyond the internal network. Restrict access to the EBS application tier using IP allowlisting or VPN so only authenticated, authorized users can reach Product Workbench. Review audit trails for suspicious data creation, modification, or deletion by low-privilege accounts in Product Workbench, and tighten role assignments to enforce least privilege.

Affected
Oracle Product Workbench (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderate≈10,000–30,000 E-Business Suite deployments worldwide, of which only a low-thousands subset is directly internet-exposed — Oracle E-Business Suite is on-premises enterprise ERP deployed by tens of thousands of organizations globally, and public internet scans typically show only a few thousand exposed EBS login pages, with most instances behind VPNs or private…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.