ZeroHour

CVE-2026-83477

moderate

Unauthenticated Adjacent-Network Data Access in Oracle E-Business Suite Work in Process

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83477 is a high-severity (CVSS 3.1: 8.1) flaw in the Workbenches component of Oracle Work in Process, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker who has access to the physical network segment attached to the hardware where the product executes (attack vector: adjacent network, so remote internet-wide exploitation is not the primary risk). A successful attack allows unauthorized creation, deletion, or modification of critical data — or all Oracle Work in Process accessible data — as well as unauthorized read access to that data, with high impact on confidentiality and integrity but no impact on availability. Organizations running affected E-Business Suite 12.2.x releases with the Work in Process manufacturing module deployed are exposed, particularly where internal network segments are loosely restricted. No public proof-of-concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, so exploitation status is none known.

What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-83477 to all E-Business Suite 12.2.3-12.2.15 environments running Work in Process, prioritizing the WIP Workbenches component. Restrict access to the network segments hosting the EBS application and database tiers via VLAN segmentation and firewall rules so that only trusted hosts can reach them, since exploitation requires adjacent-network access. Review audit logs and WIP transactional data for unexplained creation, modification, or deletion activity dating back to before the patch was applied.

Affected
Oracle E-Business Suite Work in Process (component: Workbenches)12.2.3-12.2.15
Estimated exposure
moderateon the order of tens of thousands of on-premises E-Business Suite installations globally, with an unknown subset running the Work in Process module on… — Oracle EBS is an on-premises ERP with a customer base historically measured in the tens of thousands of organizations, and public internet scans typically show only a few thousand exposed EBS instances, so the realistically addressable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Workbenches). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Work in Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.