ZeroHour

CVE-2026-83446

moderate

Privilege Abuse Flaw in Oracle E-Business Suite Financials Common Modules 12.2.3-12.2.15

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

An easily exploitable authorization flaw in the Common Components of Oracle Financials Common Modules, part of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible through Oracle Financials Common Modules. The vulnerability (CVSS 3.1 base score 8.1) affects supported versions 12.2.3 through 12.2.15 and requires only a low-privileged account, so any authenticated user of an exposed EBS instance is a potential attack vector. Availability is not impacted (C:H/I:H/A:N). There is no evidence of in-the-wild exploitation and no public proof of concept is known.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83446 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running Financials Common Modules. Restrict HTTP access to EBS self-service and module pages to VPN or trusted networks so low-privileged accounts cannot reach the vulnerable component from the open internet. Review EBS audit trails and account privileges for unexpected data creation, modification, or deletion in Financials Common Modules, and enforce least-privilege roles for users who need HTTP access.

Affected
Oracle Financials Common Modules (Oracle E-Business Suite, component: Common Components)12.2.3-12.2.15
Estimated exposure
moderate≈ several thousand to low tens of thousands of internet-exposed Oracle EBS servers, with affected 12.2.x Financials deployments a subset — Oracle E-Business Suite is enterprise software with a limited customer base, but public internet scans (Shodan/Censys) have historically shown on the order of 5,000-15,000 EBS web endpoints reachable online, many of which run 12.2.x; many…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.