ZeroHour

CVE-2026-83452

moderate

Unauthenticated Takeover Flaw in Oracle EBS Document Management and Collaboration

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83452 is a critical (CVSS 9.8) flaw in the Internal Operations component of the Oracle Document Management and Collaboration product within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks allow complete takeover of the Document Management and Collaboration component with high impact to confidentiality, integrity, and availability. Organizations running affected EBS releases that expose these services to a network — especially internet-facing HTTP endpoints — are at risk of full compromise of sensitive documents and collaboration data. The flaw is addressed in Oracle's Critical Patch Update cycle, but the specific flaw type (e.g., injection or deserialization) was not disclosed by Oracle. No public proof-of-concept or confirmed in-the-wild exploitation has been reported, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-83452 to all EBS 12.2.3-12.2.15 environments running Document Management and Collaboration, prioritizing internet-facing instances. Restrict HTTP access to EBS DMC/Internal Operations endpoints via firewall rules or VPN so they are not reachable unauthenticated from untrusted networks. Review access logs for anomalous unauthenticated requests to the affected component and rotate credentials for accounts associated with it if compromise is suspected.

Affected
Oracle E-Business Suite - Oracle Document Management and Collaboration (Internal Operations component)12.2.3-12.2.15
Estimated exposure
moderatelikely low thousands of internet-exposed EBS instances; tens of thousands of total EBS deployments (estimate) — Oracle E-Business Suite is on-premises enterprise software with a large but finite customer base, and public internet scans typically show only a few thousand EBS login endpoints exposed, most of which sit behind VPNs or internal networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.