CVE-2026-83438
moderateData Access/Manipulation Flaw in Oracle Engineering (E-Business Suite) 12.2.3-12.2.15
A difficult-to-exploit vulnerability in the Internal Operations component of Oracle Engineering, part of Oracle E-Business Suite, allows a low-privileged (authenticated) attacker with network access via HTTP to compromise Oracle Engineering. The flaw carries a scope change, meaning successful attacks may significantly impact products beyond Oracle Engineering itself. Successful exploitation can yield unauthorized creation, deletion, or modification of critical data — or all Oracle Engineering-accessible data — as well as unauthorized read access to that data, reflected in a CVSS 3.1 base score of 8.2 with high confidentiality and integrity impact but no availability impact. Affected deployments are Oracle E-Business Suite releases 12.2.3 through 12.2.15 running the Oracle Engineering product. No public proof of concept is known, the CVE is not on CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update containing the fix for CVE-2026-83438 to every E-Business Suite 12.2.3-12.2.15 instance running Oracle Engineering. Restrict HTTP access to EBS environments using VPN or IP allowlisting and enforce least-privilege roles for low-privileged accounts. Review audit logs for unexpected creation, modification, or deletion of engineering data and for anomalous activity from low-privilege users.
| Oracle Engineering (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering. While the vulnerability is in Oracle Engineering, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Engineering accessible data as well as unauthorized access to critical data or complete access to all Oracle Engineering accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.