CVE-2026-83456
nicheAuthenticated takeover flaw in Oracle Demand Signal Repository 12.2
CVE-2026-83456 is a high-severity (CVSS 3.1 base 8.8) vulnerability in the Internal Operations component of Oracle Demand Signal Repository, a product within Oracle E-Business Suite. A low-privileged attacker with network access via HTTP who holds valid credentials can easily exploit the flaw to fully take over the Demand Signal Repository, with high impact on confidentiality, integrity, and availability. Supported versions 12.2.3 through 12.2.15 are affected. Because exploitation requires an authenticated low-privileged session rather than anonymous access, the pool of potential attackers is limited to users with some level of EBS access. No public proof-of-concept is known, the issue is not on CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83456 to every Demand Signal Repository instance running 12.2.3-12.2.15. Restrict HTTP access to EBS/DSR endpoints to trusted networks or VPN, and enforce least-privilege account roles since exploitation requires a low-privileged authenticated session. Review DSR Internal Operations logs for anomalous activity by low-privilege accounts and track subsequent Oracle CPU advisories for updated guidance.
| Oracle Demand Signal Repository (Oracle E-Business Suite) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in takeover of Oracle Demand Signal Repository. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.