ZeroHour

CVE-2026-83462

moderate

Unauthenticated Takeover in Oracle EBS Mobile Application Server (MWA Terminal Server)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83462 is a critical (CVSS 9.8) vulnerability in the MWA Terminal Server component of the Oracle Mobile Application Server, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. An unauthenticated remote attacker who can reach the MWA Terminal Server's TCP port over the network can exploit the flaw without any user interaction or credentials, and a successful attack results in a complete takeover of the Oracle Mobile Application Server with high impact to confidentiality, integrity, and availability. Because exploitation is described as easy and requires no privileges, any EBS environment running an affected version with the MWA service reachable (especially from the internet) is at serious risk of full server compromise. Organizations running EBS 12.2.3-12.2.15 in warehouse, manufacturing, or mobile data-collection deployments are the primary affected population. There is no known public proof-of-concept and the flaw is not on the CISA KEV list, so exploitation status is currently none known.

What to do: Apply Oracle's Critical Patch Update that fixes CVE-2026-83462 to all EBS 12.2.3-12.2.15 environments running the Mobile Application Server. Until patched, block external access to the MWA Terminal Server TCP port at the firewall and restrict it to trusted internal networks or VPN clients, or shut down the MWA service if mobile/warehouse functionality is not in use. Review logs for unexpected TCP connections and anomalous terminal sessions on the MWA port to rule out prior exploitation.

Affected
Oracle E-Business Suite - Oracle Mobile Application Server (MWA Terminal Server component)12.2.3-12.2.15
Estimated exposure
moderate≈ low thousands of internet-reachable MWA Terminal Server endpoints, within a broader population of tens of thousands of on-premises EBS 12.2 deployments — Oracle E-Business Suite is deployed at tens of thousands of enterprises worldwide, but the MWA Terminal Server is an optional component typically used for warehouse/mobile scanning and is usually internal-facing, so only a small fraction…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.