CVE-2026-83440
moderateHigh-Privilege Takeover Flaw in Oracle E-Business Suite Product Hub
CVE-2026-83440 is a vulnerability in the Internal Operations component of Oracle Product Hub, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. Oracle rates it 'easily exploitable' by a remote attacker with network access via HTTP, but exploitation requires an attacker who already holds high privileges in the environment. A successful attack allows complete takeover of Oracle Product Hub, with high impact on the confidentiality, integrity, and availability of that component (CVSS 3.1 base score 7.2). Organizations running affected EBS 12.2 releases with Product Hub deployed are the affected population. There is no known public proof of concept and no indication of exploitation in the wild; the flaw is not on the CISA KEV list.
What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-83440 to every EBS environment running Product Hub on 12.2.3-12.2.15. Restrict HTTP access to the EBS application tier to trusted networks or VPNs, and enforce least privilege for accounts holding high-privilege Product Hub internal-operations roles since the flaw requires an already-privileged attacker. Review Product Hub and EBS audit logs for anomalous activity by high-privileged accounts as a post-patch verification step.
| Oracle E-Business Suite Product Hub (Internal Operations component) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.