ZeroHour

CVE-2026-83437

moderate

Authenticated Data Disclosure in Oracle E-Business Suite Engineering (Change Management)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83437 is a high-severity information disclosure flaw in the Change Management component of Oracle Engineering, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged, authenticated attacker with network access over HTTP, and because the vulnerability changes scope, a successful attack can also impact data beyond Oracle Engineering itself. The impact is confidentiality only: unauthorized access to critical data or complete access to all data reachable through Oracle Engineering (CVSS 3.1: 7.7, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). Affected organizations are those running the affected 12.2.3-12.2.15 releases, particularly deployments that expose EBS HTTP endpoints to broader networks. No public proof of concept is known and the flaw is not on the CISA KEV catalog, so exploitation in the wild is not currently evidenced.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83437 to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances reachable over HTTP. Review audit and access logs for low-privilege accounts that queried or exported Engineering/Change Management data or data outside that module (scope change). Restrict network access to EBS web endpoints and enforce least-privilege roles for accounts that can reach the Change Management functionality.

Affected
Oracle E-Business Suite (Oracle Engineering, Change Management component)12.2.3-12.2.15
Estimated exposure
moderate≈ thousands to low tens of thousands of E-Business Suite deployments, a subset running the Engineering module — Oracle E-Business Suite is deployed by thousands of enterprises and public scans routinely show several thousand internet-exposed EBS endpoints, but only a subset of those run the Oracle Engineering/Change Management module, so exposure is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering. While the vulnerability is in Oracle Engineering, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Engineering accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.