ZeroHour

CVE-2026-83479

moderate

Authenticated Takeover Flaw in Oracle Contracts (E-Business Suite 12.2.14-12.2.15)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83479 is a high-severity (CVSS 8.8) vulnerability in the Oracle Contracts product of Oracle E-Business Suite, in the Internal Operations component, affecting supported versions 12.2.14 through 12.2.15. It is easily exploitable by a low-privileged attacker who has network access to the E-Business Suite over HTTP, requiring only a valid low-privilege account and no user interaction. A successful attack allows the attacker to fully compromise Oracle Contracts, with high impact on the confidentiality, integrity, and availability of the affected module's data and functions. Organizations running E-Business Suite 12.2.14 or 12.2.15 with the Oracle Contracts product exposed to users or networks are affected. There is no evidence of in-the-wild exploitation, and no public proof-of-concept is known at this time.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83479 to all E-Business Suite 12.2.14 and 12.2.15 environments running Oracle Contracts. Restrict HTTP access to EBS to trusted networks/VPN and enforce least-privilege on EBS user accounts, since exploitation requires only a low-privileged login. Review Oracle Contracts audit logs and Internal Operations activity for anomalous actions by low-privilege accounts as an indicator of compromise.

Affected
Oracle E-Business Suite - Oracle Contracts (component: Internal Operations)12.2.14 - 12.2.15
Estimated exposure
moderate≈1,000-5,000 internet-exposed EBS instances, with an unknown subset licensed for the Oracle Contracts module — Oracle E-Business Suite is deployed at thousands of mid-size and large enterprises, and public internet scans (e.g., Shodan/Shadowserver fingerprinting of EBS login pages) typically show only a few thousand internet-facing EBS instances,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.