ZeroHour

CVE-2026-83454

moderate

Authenticated HTTP Flaw Enables Full Takeover of Oracle EBS Document Management

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83454 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Internal Operations component of Oracle Document Management and Collaboration, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A remote attacker with only a low-privileged account and HTTP network access to the EBS instance can exploit the flaw, which Oracle describes as easily exploitable with no user interaction required. A successful attack results in complete takeover of Oracle Document Management and Collaboration, with high impact on the confidentiality, integrity, and availability of that component. Affected organizations are enterprises running the listed EBS 12.2 releases who have not yet applied Oracle's fix, with the risk concentrated where EBS instances are reachable over the network. No public proof-of-concept is known and the flaw is not on CISA's KEV list, so there is no indication of active exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83454 to all E-Business Suite 12.2.3-12.2.15 environments. Restrict HTTP access to EBS so that self-service and low-privileged users cannot reach the Document Management and Collaboration Internal Operations endpoints, and review audit logs for anomalous activity by low-privilege accounts against that component. Since exploitation requires only a low-privileged login, verify that dormant or generic user accounts with EBS access are disabled or have strong credentials and MFA where feasible.

Affected
Oracle Document Management and Collaboration (Oracle E-Business Suite, component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderate≈10,000+ organizations running affected EBS 12.2.x, with likely low-thousands of directly internet-exposed instances — Oracle E-Business Suite is on-premises enterprise software deployed at tens of thousands of organizations worldwide, and public internet scans (Shodan/Censys) historically show a few thousand EBS login pages exposed, so only a subset of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.