ZeroHour

CVE-2026-83440

moderate

High-Privilege Takeover Flaw in Oracle E-Business Suite Product Hub

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83440 is a vulnerability in the Internal Operations component of Oracle Product Hub, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. Oracle rates it 'easily exploitable' by a remote attacker with network access via HTTP, but exploitation requires an attacker who already holds high privileges in the environment. A successful attack allows complete takeover of Oracle Product Hub, with high impact on the confidentiality, integrity, and availability of that component (CVSS 3.1 base score 7.2). Organizations running affected EBS 12.2 releases with Product Hub deployed are the affected population. There is no known public proof of concept and no indication of exploitation in the wild; the flaw is not on the CISA KEV list.

What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-83440 to every EBS environment running Product Hub on 12.2.3-12.2.15. Restrict HTTP access to the EBS application tier to trusted networks or VPNs, and enforce least privilege for accounts holding high-privilege Product Hub internal-operations roles since the flaw requires an already-privileged attacker. Review Product Hub and EBS audit logs for anomalous activity by high-privileged accounts as a post-patch verification step.

Affected
Oracle E-Business Suite Product Hub (Internal Operations component)12.2.3-12.2.15
Estimated exposure
moderate≈1,000-10,000+ installations (subset of internet-exposed Oracle EBS instances running Product Hub on 12.2.3-12.2.15) — Public internet scan data (e.g., Shodan) has historically shown on the order of 10,000 internet-facing Oracle EBS application-tier hosts, and only the subset of those running the affected 12.2.3-12.2.15 releases with Product Hub is in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.