CVE-2026-83464
moderateUnauthenticated Takeover Flaw in Oracle E-Business Suite Mobile Application Server (MWA)
CVE-2026-83464 is a difficult-to-exploit, unauthenticated vulnerability in the MWA Terminal Server component of the Oracle Mobile Application Server within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. An attacker who can reach the service over the network via TCP — with no credentials or user interaction required — could exploit a flaw in the telnet-style terminal server to fully compromise the Mobile Application Server, impacting confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). The high attack complexity (AC:H) means reliable exploitation likely requires significant skill, timing, or knowledge of the target environment rather than a simple one-click attack. Organizations running EBS 12.2 with MWA enabled for mobile warehouse/barcode data collection are the affected population, particularly if the MWA TCP ports are reachable from untrusted networks. No public proof-of-concept exists and the flaw is not on the CISA KEV, so exploitation in the wild is presumed unlikely at this time.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83464 to all EBS 12.2.3-12.2.15 instances running the Mobile Application Server. Restrict MWA Terminal Server TCP ports (default 10230-10232 range) to trusted internal subnets and mobile-device VLANs via firewall rules, and verify none are exposed to the internet with an external port scan. Review MWA service logs for anomalous connection attempts or unexpected sessions from unknown source IPs as an indicator of probing.
| Oracle E-Business Suite — Oracle Mobile Application Server (MWA Terminal Server component) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.