CVE-2026-83452
moderateUnauthenticated Takeover Flaw in Oracle EBS Document Management and Collaboration
CVE-2026-83452 is a critical (CVSS 9.8) flaw in the Internal Operations component of the Oracle Document Management and Collaboration product within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks allow complete takeover of the Document Management and Collaboration component with high impact to confidentiality, integrity, and availability. Organizations running affected EBS releases that expose these services to a network — especially internet-facing HTTP endpoints — are at risk of full compromise of sensitive documents and collaboration data. The flaw is addressed in Oracle's Critical Patch Update cycle, but the specific flaw type (e.g., injection or deserialization) was not disclosed by Oracle. No public proof-of-concept or confirmed in-the-wild exploitation has been reported, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.
What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-83452 to all EBS 12.2.3-12.2.15 environments running Document Management and Collaboration, prioritizing internet-facing instances. Restrict HTTP access to EBS DMC/Internal Operations endpoints via firewall rules or VPN so they are not reachable unauthenticated from untrusted networks. Review access logs for anomalous unauthenticated requests to the affected component and rotate credentials for accounts associated with it if compromise is suspected.
| Oracle E-Business Suite - Oracle Document Management and Collaboration (Internal Operations component) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.