CVE-2026-83437
moderateAuthenticated Data Disclosure in Oracle E-Business Suite Engineering (Change Management)
CVE-2026-83437 is a high-severity information disclosure flaw in the Change Management component of Oracle Engineering, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged, authenticated attacker with network access over HTTP, and because the vulnerability changes scope, a successful attack can also impact data beyond Oracle Engineering itself. The impact is confidentiality only: unauthorized access to critical data or complete access to all data reachable through Oracle Engineering (CVSS 3.1: 7.7, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). Affected organizations are those running the affected 12.2.3-12.2.15 releases, particularly deployments that expose EBS HTTP endpoints to broader networks. No public proof of concept is known and the flaw is not on the CISA KEV catalog, so exploitation in the wild is not currently evidenced.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83437 to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances reachable over HTTP. Review audit and access logs for low-privilege accounts that queried or exported Engineering/Change Management data or data outside that module (scope change). Restrict network access to EBS web endpoints and enforce least-privilege roles for accounts that can reach the Change Management functionality.
| Oracle E-Business Suite (Oracle Engineering, Change Management component) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering. While the vulnerability is in Oracle Engineering, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Engineering accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.