ZeroHour

CVE-2026-83450

moderate

Privileged Takeover Flaw in Oracle EBS Bills of Material Setup Workbench

CVSS 3.1
8.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83450 is a vulnerability in the Setup Workbench component of Oracle Bills of Material, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is triggered over the network via HTTP by an attacker who already holds high privileges within the EBS environment, and successful exploitation allows a complete takeover of the Oracle Bills of Material product. Because the vulnerability carries a scope change (S:C), a successful attack may also significantly impact additional Oracle E-Business Suite products beyond Bills of Material, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 8.0). The attack path is rated difficult to exploit (AC:H), which tempers practical risk somewhat, but the combination of authenticated network access and cross-scope impact makes it serious for exposed EBS estates. No public proof of concept is known, the flaw is not on the CISA KEV list, and there is no indication of in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-83450 to all EBS 12.2.3-12.2.15 environments. In the interim, restrict HTTP access to EBS via VPN/IP allowlisting, audit and minimize privileged EBS accounts with Bills of Material and Setup Workbench responsibilities, and monitor access logs for suspicious activity from those accounts. Verify scope-change risk by reviewing what downstream EBS products share data or integration paths with Bills of Material.

Affected
Oracle E-Business Suite Bills of Material (Setup Workbench component)12.2.3 - 12.2.15
Estimated exposure
moderateTens of thousands of Oracle EBS installations worldwide, with a few thousand internet-exposed instances (order of magnitude ~10,000-50,000 installs) — Oracle E-Business Suite is deployed at tens of thousands of mid-to-large enterprises globally (release 12.2 being the long-supported line), while public internet scans typically show only a few thousand EBS web front-ends reachable over…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.