ZeroHour

CVE-2026-83438

moderate

Data Access/Manipulation Flaw in Oracle Engineering (E-Business Suite) 12.2.3-12.2.15

CVSS 3.1
8.2 high
EPSS
Published
()
Modified
AI analysis

A difficult-to-exploit vulnerability in the Internal Operations component of Oracle Engineering, part of Oracle E-Business Suite, allows a low-privileged (authenticated) attacker with network access via HTTP to compromise Oracle Engineering. The flaw carries a scope change, meaning successful attacks may significantly impact products beyond Oracle Engineering itself. Successful exploitation can yield unauthorized creation, deletion, or modification of critical data — or all Oracle Engineering-accessible data — as well as unauthorized read access to that data, reflected in a CVSS 3.1 base score of 8.2 with high confidentiality and integrity impact but no availability impact. Affected deployments are Oracle E-Business Suite releases 12.2.3 through 12.2.15 running the Oracle Engineering product. No public proof of concept is known, the CVE is not on CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update containing the fix for CVE-2026-83438 to every E-Business Suite 12.2.3-12.2.15 instance running Oracle Engineering. Restrict HTTP access to EBS environments using VPN or IP allowlisting and enforce least-privilege roles for low-privileged accounts. Review audit logs for unexpected creation, modification, or deletion of engineering data and for anomalous activity from low-privilege users.

Affected
Oracle Engineering (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderate≈ low thousands of installations (subset of the EBS 12.2 install base running Oracle Engineering) — Oracle E-Business Suite is an on-premises enterprise ERP with an install base estimated in the low tens of thousands of organizations worldwide, but Oracle Engineering is an optional product used by a subset (typically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering. While the vulnerability is in Oracle Engineering, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Engineering accessible data as well as unauthorized access to critical data or complete access to all Oracle Engineering accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.