ZeroHour

CVE-2026-83449

large

Low-Privilege Data Exposure Flaw in Oracle EBS Bills of Material 12.2.3-12.2.15

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

A vulnerability in the Internal Operations component of Oracle Bills of Material, part of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to easily compromise the product. The vector carries a scope change, meaning successful attacks may significantly impact additional Oracle E-Business Suite products beyond Bills of Material itself. An attacker who succeeds gains unauthorized access to critical data or complete access to all Oracle Bills of Material-accessible data, as well as the unauthorized ability to cause a partial denial of service. Affected deployments are Oracle E-Business Suite releases 12.2.3 through 12.2.15 (CVSS 3.1 base score 8.5, high). No public proof of concept exists, there is no confirmed in-the-wild exploitation, and the CVE is not on the CISA Known Exploited Vulnerabilities list.

What to do: Apply the Oracle Critical Patch Update containing the fix for CVE-2026-83449 to every Oracle E-Business Suite 12.2.3-12.2.15 environment as soon as it is available. Until patched, restrict HTTP access to EBS to trusted networks or VPN, audit and minimize low-privileged EBS account grants, and monitor logs for anomalous access to Bills of Material functions, unusual data retrieval, or degradation suggestive of partial denial of service.

Affected
Oracle Bills of Material (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
large≈ tens of thousands of EBS installations worldwide, with likely only a few thousand 12.2.x web endpoints internet-exposed — Oracle E-Business Suite is deployed at an estimated tens of thousands of organizations globally and public internet scans routinely identify thousands of internet-facing EBS web endpoints, though only 12.2.3-12.2.15 and authenticated…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Bills of Material. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.