ZeroHour

CVE-2026-83456

niche

Authenticated takeover flaw in Oracle Demand Signal Repository 12.2

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83456 is a high-severity (CVSS 3.1 base 8.8) vulnerability in the Internal Operations component of Oracle Demand Signal Repository, a product within Oracle E-Business Suite. A low-privileged attacker with network access via HTTP who holds valid credentials can easily exploit the flaw to fully take over the Demand Signal Repository, with high impact on confidentiality, integrity, and availability. Supported versions 12.2.3 through 12.2.15 are affected. Because exploitation requires an authenticated low-privileged session rather than anonymous access, the pool of potential attackers is limited to users with some level of EBS access. No public proof-of-concept is known, the issue is not on CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83456 to every Demand Signal Repository instance running 12.2.3-12.2.15. Restrict HTTP access to EBS/DSR endpoints to trusted networks or VPN, and enforce least-privilege account roles since exploitation requires a low-privileged authenticated session. Review DSR Internal Operations logs for anomalous activity by low-privilege accounts and track subsequent Oracle CPU advisories for updated guidance.

Affected
Oracle Demand Signal Repository (Oracle E-Business Suite)12.2.3-12.2.15
Estimated exposure
niche≈ hundreds to low thousands of enterprise deployments (DSR is a separately licensed, retail/CPG-focused subset of E-Business Suite installs) — Oracle E-Business Suite runs at tens of thousands of organizations with many internet-reachable instances in public scans, but Demand Signal Repository is an optional add-on used mainly by consumer-goods and retail companies, so only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in takeover of Oracle Demand Signal Repository. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.