CVE-2026-83449
largeLow-Privilege Data Exposure Flaw in Oracle EBS Bills of Material 12.2.3-12.2.15
A vulnerability in the Internal Operations component of Oracle Bills of Material, part of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to easily compromise the product. The vector carries a scope change, meaning successful attacks may significantly impact additional Oracle E-Business Suite products beyond Bills of Material itself. An attacker who succeeds gains unauthorized access to critical data or complete access to all Oracle Bills of Material-accessible data, as well as the unauthorized ability to cause a partial denial of service. Affected deployments are Oracle E-Business Suite releases 12.2.3 through 12.2.15 (CVSS 3.1 base score 8.5, high). No public proof of concept exists, there is no confirmed in-the-wild exploitation, and the CVE is not on the CISA Known Exploited Vulnerabilities list.
What to do: Apply the Oracle Critical Patch Update containing the fix for CVE-2026-83449 to every Oracle E-Business Suite 12.2.3-12.2.15 environment as soon as it is available. Until patched, restrict HTTP access to EBS to trusted networks or VPN, audit and minimize low-privileged EBS account grants, and monitor logs for anomalous access to Bills of Material functions, unusual data retrieval, or degradation suggestive of partial denial of service.
| Oracle Bills of Material (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Bills of Material. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.