CVE-2026-83454
moderateAuthenticated HTTP Flaw Enables Full Takeover of Oracle EBS Document Management
CVE-2026-83454 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Internal Operations component of Oracle Document Management and Collaboration, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A remote attacker with only a low-privileged account and HTTP network access to the EBS instance can exploit the flaw, which Oracle describes as easily exploitable with no user interaction required. A successful attack results in complete takeover of Oracle Document Management and Collaboration, with high impact on the confidentiality, integrity, and availability of that component. Affected organizations are enterprises running the listed EBS 12.2 releases who have not yet applied Oracle's fix, with the risk concentrated where EBS instances are reachable over the network. No public proof-of-concept is known and the flaw is not on CISA's KEV list, so there is no indication of active exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83454 to all E-Business Suite 12.2.3-12.2.15 environments. Restrict HTTP access to EBS so that self-service and low-privileged users cannot reach the Document Management and Collaboration Internal Operations endpoints, and review audit logs for anomalous activity by low-privilege accounts against that component. Since exploitation requires only a low-privileged login, verify that dormant or generic user accounts with EBS access are disabled or have strong credentials and MFA where feasible.
| Oracle Document Management and Collaboration (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.