ZeroHour

CVE-2026-83448

moderate

Low-Privilege Data Tampering Flaw in Oracle E-Business Suite Bills of Material

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83448 is a vulnerability in the Internal Operations component of Oracle Bills of Material, part of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, who can send crafted requests to compromise the Bills of Material module. A successful attack yields unauthorized creation, deletion, or modification of critical data — or all data accessible through Oracle Bills of Material — as well as unauthorized read access to that data, with high impact to both confidentiality and integrity (CVSS 3.1 base score 8.1; availability is not affected). Organizations running affected 12.2.x releases with the manufacturing/BOM module exposed to users over HTTP are at risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not on the CISA KEV catalog.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83448 to all EBS 12.2.3-12.2.15 environments. Restrict HTTP access to EBS so only trusted networks/VPN users can reach it, and audit least-privilege roles since exploitation requires only a low-privileged account. Review Bills of Material data for unauthorized creation, modification, or deletion and monitor for anomalous access by low-privilege users.

Affected
Oracle E-Business Suite Bills of Material (component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderatelow thousands of installations (roughly 1,000-10,000 EBS instances with the BOM module) — Oracle E-Business Suite deployments number in the tens of thousands globally with a subset internet-facing per public scan data, and only those running release 12.2 with the Bills of Material manufacturing module in use are affected, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Bills of Material accessible data as well as unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.