ZeroHour

CVE-2026-83442

moderate

High-Privilege Takeover Flaw in Oracle Product Hub (E-Business Suite 12.2)

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83442 is a vulnerability in the Internal Operations component of Oracle Product Hub, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. Oracle rates it as easily exploitable by an authenticated, high-privileged attacker who has network access to the E-Business Suite web tier via HTTP. A successful attack allows that attacker to fully compromise Oracle Product Hub, with high impact on the confidentiality, integrity, and availability of the application (CVSS 3.1 base score 7.2). The privilege requirement means the realistic threat is an insider, a compromised privileged account, or an attacker who has already gained EBS credentials pivoting to full product takeover. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83442 to every Oracle E-Business Suite environment running Product Hub 12.2.3-12.2.15, prioritizing internet-facing web tiers. Enforce least privilege for accounts with Product Hub / Internal Operations responsibilities, restrict HTTP access to EBS internal endpoints (for example via network segmentation or allow-listing), and rotate credentials for privileged EBS accounts. Review EBS audit logs for anomalous actions by high-privileged users around Product Hub functions to rule out prior abuse.

Affected
Oracle Product Hub (Oracle E-Business Suite, component: Internal Operations)12.2.3 - 12.2.15
Estimated exposure
moderate≈ thousands of installations (likely low thousands of internet-exposed E-Business Suite web endpoints) — Oracle publishes no install counts, so this is based on the widely cited Oracle E-Business Suite installed base (tens of thousands of organizations, most on 12.2.x) and public internet scan data historically showing low thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.