CVE-2026-83451
moderateAuthenticated Takeover Flaw in Oracle Product Workbench for E-Business Suite 12.2
Oracle Product Workbench, part of Oracle E-Business Suite (Internal Operations component), contains a difficult-to-exploit flaw in versions 12.2.3 through 12.2.15 that allows a low-privileged attacker with network access via HTTP to fully compromise the Product Workbench application. Exploitation requires an authenticated low-privilege account and high attack complexity (CVSS 3.1: 8.5, AV:N/AC:H/PR:L/S:C), but the scope change means successful attacks can significantly impact additional Oracle E-Business Suite products beyond Product Workbench itself. A successful attack results in complete takeover of Oracle Product Workbench with high impacts to confidentiality, integrity, and availability. Organizations running E-Business Suite 12.2.3-12.2.15 with Product Workbench reachable over HTTP, especially by authenticated internal or partner users, are affected. No public proof of concept exists and the CVE is not on CISA's KEV list, so exploitation is not known to be occurring in the wild.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83451 to every E-Business Suite environment on 12.2.3-12.2.15 where Product Workbench is installed. Restrict HTTP access to EBS (VPN, IP allowlisting, WAF rules) so low-privileged users on untrusted networks cannot reach the Internal Operations component of Product Workbench. Review EBS audit and access logs for anomalous activity by low-privileged authenticated accounts against Product Workbench pages, and verify that no unauthorized privilege changes or account takeovers have occurred.
| Oracle Product Workbench (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. While the vulnerability is in Oracle Product Workbench, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Product Workbench. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.