CVE-2026-83453
moderateHigh-Privilege Takeover in Oracle E-Business Suite Document Management and Collaboration
CVE-2026-83453 is a vulnerability in the Internal Operations component of Oracle Document Management and Collaboration (DMC), part of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is remotely exploitable over HTTP by an attacker who already holds high privileges, and Oracle rates it as easily exploitable. A successful attack allows the attacker to fully compromise the DMC component, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). Because exploitation requires an authenticated, high-privileged account, the practical risk is privilege escalation and consolidation inside an already-compromised EBS environment rather than an anonymous internet attack. The flaw is not on the CISA KEV list, no public proof-of-concept exists, and no in-the-wild exploitation is known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83453 to all E-Business Suite 12.2.3-12.2.15 environments running Document Management and Collaboration. Restrict HTTP access to the DMC/Internal Operations endpoints to trusted networks and administrative users only, and audit high-privileged EBS accounts for signs of misuse or unexpected logins. Verify that no interim patches were skipped, since this component requires the full cumulative CPU patching sequence.
| Oracle E-Business Suite Document Management and Collaboration | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.