CVE-2026-83432
nicheAuthenticated Access Control Flaw in Oracle Depot Repair (Oracle E-Business Suite)
CVE-2026-83432 is a vulnerability in the Estimate and Actual Charges component of Oracle Depot Repair, a module of Oracle E-Business Suite, affecting supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP — meaning any authenticated EBS user with minimal permissions — can easily exploit the flaw to compromise Oracle Depot Repair. A successful attack yields unauthorized creation, deletion, or modification of critical data, plus unauthorized read access to critical data or all Oracle Depot Repair accessible data, giving high confidentiality and integrity impact (CVSS 3.1 base score 8.1) with no availability impact. Organizations running EBS 12.2 with the Depot Repair module deployed are affected. No public proof of concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating no known in-the-wild exploitation to date.
What to do: Apply the Oracle Critical Patch Update that remediated this CVE to all EBS 12.2.3-12.2.15 environments running Depot Repair. Restrict HTTP access to EBS to trusted networks or VPN rather than exposing it to the internet, and review low-privileged account permissions for least-privilege enforcement. Audit Depot Repair logs for anomalous changes or reads of Estimate and Actual Charges data to rule out prior compromise.
| Oracle Depot Repair (Oracle E-Business Suite, component: Estimate and Actual Charges) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Depot Repair accessible data as well as unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.