CVE-2026-83465
moderateUnauthenticated DoS/CSRF-Style Flaw in Oracle EBS Mobile Application Server
CVE-2026-83465 is a high-severity (CVSS 8.2) vulnerability in the MWA Terminal Server component of the Oracle Mobile Application Server within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. An unauthenticated attacker with network access over HTTP can exploit the flaw, though successful attacks require human interaction from a victim other than the attacker — a pattern consistent with CSRF-style targeting of mobile/warehouse terminal sessions. Because the scope changes (S:C), a successful attack may significantly impact products beyond the Mobile Application Server itself. The practical impact is unauthorized update, insert, or delete access to some data accessible through the server, plus the ability to cause a hang or frequently repeatable crash (complete denial of service). No public proof-of-concept exists and the vulnerability is not in the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently known to be occurring.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83465 to all EBS 12.2.3-12.2.15 environments. Verify that the MWA Terminal Server port is not exposed to the internet and restrict it to trusted warehouse/mobile device networks via firewall rules. Review application and database logs for unexpected data modifications or repeated Mobile Application Server crashes that could indicate an exploitation attempt.
| Oracle E-Business Suite (Oracle Mobile Application Server, MWA Terminal Server component) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Application Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Mobile Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Mobile Application Server as well as unauthorized update, insert or delete access to some of Oracle Mobile Application Server accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.