ZeroHour

CVE-2026-83432

niche

Authenticated Access Control Flaw in Oracle Depot Repair (Oracle E-Business Suite)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83432 is a vulnerability in the Estimate and Actual Charges component of Oracle Depot Repair, a module of Oracle E-Business Suite, affecting supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP — meaning any authenticated EBS user with minimal permissions — can easily exploit the flaw to compromise Oracle Depot Repair. A successful attack yields unauthorized creation, deletion, or modification of critical data, plus unauthorized read access to critical data or all Oracle Depot Repair accessible data, giving high confidentiality and integrity impact (CVSS 3.1 base score 8.1) with no availability impact. Organizations running EBS 12.2 with the Depot Repair module deployed are affected. No public proof of concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating no known in-the-wild exploitation to date.

What to do: Apply the Oracle Critical Patch Update that remediated this CVE to all EBS 12.2.3-12.2.15 environments running Depot Repair. Restrict HTTP access to EBS to trusted networks or VPN rather than exposing it to the internet, and review low-privileged account permissions for least-privilege enforcement. Audit Depot Repair logs for anomalous changes or reads of Estimate and Actual Charges data to rule out prior compromise.

Affected
Oracle Depot Repair (Oracle E-Business Suite, component: Estimate and Actual Charges)12.2.3-12.2.15
Estimated exposure
nichelikely hundreds to low thousands of installations — Oracle E-Business Suite is deployed at roughly tens of thousands of organizations worldwide, but Depot Repair is an optional, narrowly used service/repair module, so only a small fraction of EBS shops run it — a precise count is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Depot Repair accessible data as well as unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.