CVE-2026-83450
moderatePrivileged Takeover Flaw in Oracle EBS Bills of Material Setup Workbench
CVE-2026-83450 is a vulnerability in the Setup Workbench component of Oracle Bills of Material, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is triggered over the network via HTTP by an attacker who already holds high privileges within the EBS environment, and successful exploitation allows a complete takeover of the Oracle Bills of Material product. Because the vulnerability carries a scope change (S:C), a successful attack may also significantly impact additional Oracle E-Business Suite products beyond Bills of Material, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 8.0). The attack path is rated difficult to exploit (AC:H), which tempers practical risk somewhat, but the combination of authenticated network access and cross-scope impact makes it serious for exposed EBS estates. No public proof of concept is known, the flaw is not on the CISA KEV list, and there is no indication of in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-83450 to all EBS 12.2.3-12.2.15 environments. In the interim, restrict HTTP access to EBS via VPN/IP allowlisting, audit and minimize privileged EBS accounts with Bills of Material and Setup Workbench responsibilities, and monitor access logs for suspicious activity from those accounts. Verify scope-change risk by reviewing what downstream EBS products share data or integration paths with Bills of Material.
| Oracle E-Business Suite Bills of Material (Setup Workbench component) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.