ZeroHour

CVE-2026-83463

niche

Unauthenticated Takeover in Oracle E-Business Suite Mobile Application Server (MWA Terminal Server)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83463 is a difficult-to-exploit, unauthenticated vulnerability in the MWA Terminal Server component of the Oracle Mobile Application Server within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. To exploit it, an attacker must already have access to the physical communication segment (local/adjacent network) attached to the host running the Mobile Application Server, so it cannot be triggered directly from the open internet. A successful attack allows full takeover of the Oracle Mobile Application Server, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5, vector AV:A/AC:H/PR:N/UI:N/S:U). Organizations running affected E-Business Suite 12.2 releases with the MWA Terminal Server enabled for mobile supply chain/warehouse handhelds are at risk. No public proof-of-concept exists and no exploitation in the wild has been reported, and the flaw is not on the CISA KEV list.

What to do: Apply the Oracle Critical Patch Update that resolves CVE-2026-83463 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running the Mobile Application Server. In the meantime, restrict access to the MWA Terminal Server listener ports (commonly in the 10300+ range) so only trusted handheld-device subnets can reach them, and isolate that segment from general corporate networks. Review logs for unexpected MWA sessions or connections from unauthorized hosts on the adjacent segment.

Affected
Oracle E-Business Suite - Oracle Mobile Application Server (MWA Terminal Server)12.2.3-12.2.15
Estimated exposure
nichelikely low thousands of installations worldwide (subset of E-Business Suite 12.2 deployments using the MWA Terminal Server) — Oracle E-Business Suite is deployed by thousands of enterprises, but the MWA Terminal Server is an optional component typically used only where Oracle mobile supply chain applications are in use, and exploitation requires adjacency to the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Mobile Application Server executes to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.