ZeroHour

CVE-2026-83445

niche

Authenticated Takeover Flaw in Oracle E-Business Suite CMRO 12.2.3-12.2.15

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83445 is a high-severity (CVSS 8.8) vulnerability in the Internal Operations component of Oracle Complex Maintenance, Repair and Overhaul (CMRO), a specialized product within Oracle E-Business Suite. A remote attacker who already holds a low-privileged account can exploit it over HTTPS with no user interaction, and a successful attack results in a complete takeover of the CMRO product, with high impact on confidentiality, integrity, and availability. All supported versions 12.2.3 through 12.2.15 are affected, meaning even fully up-to-date EBS 12.2 releases are vulnerable until the Oracle Critical Patch Update is applied. Organizations in aerospace, defense, and industrial maintenance running CMRO on internet- or partner-reachable EBS instances are most exposed, since the attacker needs valid but low-level credentials. There is no known public proof of concept and the CVE is not in CISA's KEV catalog, indicating no observed in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83445 to all E-Business Suite 12.2.3-12.2.15 environments running CMRO — note that being on the latest 12.2.x version alone does not remediate this, since 12.2.15 is itself affected. Restrict HTTPS access to EBS instances via VPN, allow-listing, or reverse proxy so low-privileged accounts cannot be leverited from untrusted networks. Review low-privileged user activity and CMRO data for signs of unauthorized access or modification.

Affected
Oracle Complex Maintenance, Repair and Overhaul (Oracle E-Business Suite), Internal Operations component12.2.3-12.2.15
Estimated exposure
nichelikely hundreds to low thousands of installations worldwide — Oracle E-Business Suite is deployed at tens of thousands of enterprises, but CMRO is a specialized aviation/aerospace maintenance module with a much smaller licensed base, and Oracle publishes no install counts, so this is an estimate from…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.