CVE-2026-83463
nicheUnauthenticated Takeover in Oracle E-Business Suite Mobile Application Server (MWA Terminal Server)
CVE-2026-83463 is a difficult-to-exploit, unauthenticated vulnerability in the MWA Terminal Server component of the Oracle Mobile Application Server within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. To exploit it, an attacker must already have access to the physical communication segment (local/adjacent network) attached to the host running the Mobile Application Server, so it cannot be triggered directly from the open internet. A successful attack allows full takeover of the Oracle Mobile Application Server, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5, vector AV:A/AC:H/PR:N/UI:N/S:U). Organizations running affected E-Business Suite 12.2 releases with the MWA Terminal Server enabled for mobile supply chain/warehouse handhelds are at risk. No public proof-of-concept exists and no exploitation in the wild has been reported, and the flaw is not on the CISA KEV list.
What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-83463 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running the Mobile Application Server. In the meantime, restrict access to the MWA Terminal Server listener ports (commonly in the 10300+ range) so only trusted handheld-device subnets can reach them, and isolate that segment from general corporate networks. Review logs for unexpected MWA sessions or connections from unauthorized hosts on the adjacent segment.
| Oracle E-Business Suite - Oracle Mobile Application Server (MWA Terminal Server) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Mobile Application Server executes to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.