CVE-2026-83444
moderateLow-Privilege Takeover Flaw in Oracle Product Hub (E-Business Suite) 12.2.3-12.2.15
CVE-2026-83444 is a high-severity vulnerability in the Internal Operations component of Oracle Product Hub, part of Oracle E-Business Suite. A low-privileged (authenticated) attacker with network access via HTTP can exploit it easily to fully compromise Oracle Product Hub, with high impacts on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). All supported releases from 12.2.3 through 12.2.15 are affected. No public proof-of-concept exists, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported, though Oracle CPU flaws are frequently targeted after disclosure.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83444 to every E-Business Suite environment on 12.2.3-12.2.15 where Product Hub is installed, and verify the fix with Oracle's patch inventory tools. Until patched, restrict HTTP access to EBS via VPN/IP allowlisting and monitor low-privilege accounts for anomalous activity against Product Hub. Review Product Hub data, workflows, and account privileges for signs of unauthorized takeover.
| Oracle E-Business Suite - Oracle Product Hub (component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.