CVE-2026-83436
nicheAuthenticated Data Exposure and Partial DoS in Oracle Depot Repair (E-Business Suite)
Oracle Depot Repair within Oracle E-Business Suite contains a flaw in its Recall Management component, tracked as CVE-2026-83436, affecting releases 12.2.3 through 12.2.15. The vulnerability is easily exploitable by a low-privileged (already authenticated) attacker who can reach the E-Business Suite instance over HTTP. A successful attack gives the attacker unauthorized read access to critical — potentially all — Oracle Depot Repair accessible data, and the unauthorized ability to cause a partial denial of service against the module; integrity is not impacted (CVSS 3.1 base score 7.1: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L). Organizations running affected E-Business Suite releases with the Depot Repair product are exposed, particularly if broad internal or remote user populations have HTTP access to the environment. A fix was issued via Oracle's Critical Patch Update process; no public proof-of-concept is known, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update remediation for CVE-2026-83436 to all E-Business Suite environments on 12.2.3–12.2.15 running Depot Repair, following the relevant Patch Availability Document in My Oracle Support. Restrict HTTP access to E-Business Suite to trusted networks and users, and verify that low-privilege internal accounts cannot reach Depot Repair's Recall Management functions unless required. Review audit and access logs for unusual data reads by low-privileged accounts against Depot Repair data.
| Oracle E-Business Suite (Oracle Depot Repair, Recall Management component) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Recall Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Depot Repair. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.