ZeroHour

CVE-2026-83444

moderate

Low-Privilege Takeover Flaw in Oracle Product Hub (E-Business Suite) 12.2.3-12.2.15

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83444 is a high-severity vulnerability in the Internal Operations component of Oracle Product Hub, part of Oracle E-Business Suite. A low-privileged (authenticated) attacker with network access via HTTP can exploit it easily to fully compromise Oracle Product Hub, with high impacts on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). All supported releases from 12.2.3 through 12.2.15 are affected. No public proof-of-concept exists, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported, though Oracle CPU flaws are frequently targeted after disclosure.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83444 to every E-Business Suite environment on 12.2.3-12.2.15 where Product Hub is installed, and verify the fix with Oracle's patch inventory tools. Until patched, restrict HTTP access to EBS via VPN/IP allowlisting and monitor low-privilege accounts for anomalous activity against Product Hub. Review Product Hub data, workflows, and account privileges for signs of unauthorized takeover.

Affected
Oracle E-Business Suite - Oracle Product Hub (component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderatelikely hundreds to low thousands of affected on-premises deployments worldwide — Oracle E-Business Suite is on-premises enterprise software run by tens of thousands of organizations globally, but only a subset license Product Hub and only a fraction expose their EBS HTTP endpoints to the internet, so the vulnerable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.