ZeroHour

CVE-2026-83464

moderate

Unauthenticated Takeover Flaw in Oracle E-Business Suite Mobile Application Server (MWA)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83464 is a difficult-to-exploit, unauthenticated vulnerability in the MWA Terminal Server component of the Oracle Mobile Application Server within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. An attacker who can reach the service over the network via TCP — with no credentials or user interaction required — could exploit a flaw in the telnet-style terminal server to fully compromise the Mobile Application Server, impacting confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). The high attack complexity (AC:H) means reliable exploitation likely requires significant skill, timing, or knowledge of the target environment rather than a simple one-click attack. Organizations running EBS 12.2 with MWA enabled for mobile warehouse/barcode data collection are the affected population, particularly if the MWA TCP ports are reachable from untrusted networks. No public proof-of-concept exists and the flaw is not on the CISA KEV, so exploitation in the wild is presumed unlikely at this time.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83464 to all EBS 12.2.3-12.2.15 instances running the Mobile Application Server. Restrict MWA Terminal Server TCP ports (default 10230-10232 range) to trusted internal subnets and mobile-device VLANs via firewall rules, and verify none are exposed to the internet with an external port scan. Review MWA service logs for anomalous connection attempts or unexpected sessions from unknown source IPs as an indicator of probing.

Affected
Oracle E-Business Suite — Oracle Mobile Application Server (MWA Terminal Server component)12.2.3 - 12.2.15
Estimated exposure
moderate≈10,000+ E-Business Suite deployments worldwide, with likely only hundreds to low thousands of internet-reachable MWA Terminal Server endpoints — Oracle EBS is a enterprise ERP deployed at tens of thousands of organizations, but MWA terminal-server TCP ports are typically bound to internal networks for warehouse/mobile devices, so only a small fraction should be internet-exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.