CVE-2026-83446
moderatePrivilege Abuse Flaw in Oracle E-Business Suite Financials Common Modules 12.2.3-12.2.15
An easily exploitable authorization flaw in the Common Components of Oracle Financials Common Modules, part of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible through Oracle Financials Common Modules. The vulnerability (CVSS 3.1 base score 8.1) affects supported versions 12.2.3 through 12.2.15 and requires only a low-privileged account, so any authenticated user of an exposed EBS instance is a potential attack vector. Availability is not impacted (C:H/I:H/A:N). There is no evidence of in-the-wild exploitation and no public proof of concept is known.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83446 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running Financials Common Modules. Restrict HTTP access to EBS self-service and module pages to VPN or trusted networks so low-privileged accounts cannot reach the vulnerable component from the open internet. Review EBS audit trails and account privileges for unexpected data creation, modification, or deletion in Financials Common Modules, and enforce least-privilege roles for users who need HTTP access.
| Oracle Financials Common Modules (Oracle E-Business Suite, component: Common Components) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.