ZeroHour

CVE-2026-83481

moderate

High-Privilege Remote Takeover Vulnerability in Oracle Contracts, EBS 12.2.14-12.2.15

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83481 is a remotely exploitable flaw in the Internal Operations component of Oracle Contracts, part of Oracle E-Business Suite, affecting versions 12.2.14 through 12.2.15. It is exploited over HTTP by an attacker who already holds high privileges (i.e., an authenticated privileged account), with low attack complexity and no user interaction required. A successful attack allows the attacker to fully compromise Oracle Contracts, with high impact on the confidentiality, integrity, and availability of that product (CVSS 3.1 base score 7.2). Organizations running E-Business Suite 12.2.14 or 12.2.15 with the Oracle Contracts module deployed are affected; because exploitation requires elevated privileges, the realistic threat is from malicious insiders or attackers using stolen privileged credentials. There is no known public proof of concept, the CVE is not on CISA's KEV list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE and bring E-Business Suite to the latest 12.2.x patch level if currently on 12.2.14 or 12.2.15. Restrict HTTP access to EBS application tiers (VPN/internal networks or IP allowlisting), audit and enforce least privilege on high-privilege EBS accounts, and monitor Contracts module activity for anomalous actions by privileged users given the stolen-credential/insider exploitation path.

Affected
Oracle E-Business Suite - Oracle Contracts (component: Internal Operations)12.2.14-12.2.15
Estimated exposure
moderatelow thousands to low tens of thousands of EBS deployments (only those on 12.2.14-12.2.15 with Contracts in use) — Oracle publishes no install counts, but EBS 12.2 is the maintained on-prem release used by thousands of enterprises worldwide and public internet scans typically show only a few thousand internet-facing EBS web endpoints, with Oracle…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.