ZeroHour

CVE-2026-83482

moderate

High-Privilege Takeover Flaw in Oracle Contracts, Oracle E-Business Suite 12.2

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83482 is a vulnerability in the Internal Operations component of Oracle Contracts, part of Oracle E-Business Suite, affecting versions 12.2.14 through 12.2.15. It is easily exploitable by a high-privileged (authenticated) attacker who has network access to the E-Business Suite over HTTP, allowing them to fully compromise the Oracle Contracts product. A successful attack results in a complete takeover, with high impact on the confidentiality, integrity, and availability of Oracle Contracts data and functionality (CVSS 3.1 base score 7.2). Organizations running the affected E-Business Suite releases with the Oracle Contracts module licensed and deployed are exposed, particularly those with internet-facing or broadly reachable self-service/web tiers. No public proof-of-concept exists, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83482 to all E-Business Suite 12.2.14-12.2.15 environments as soon as your patch cycle allows. Until patched, restrict HTTP access to the EBS applications tier (especially Contracts/Internal Operations responsibilities) via network segmentation, VPN, or allow-listing, and audit accounts holding high-privileged Contracts responsibilities for misuse. Review EBS access logs for unusual activity by privileged users against Contracts functions following patching.

Affected
Oracle E-Business Suite (Oracle Contracts, component: Internal Operations)12.2.14-12.2.15
Estimated exposure
moderate≈ thousands to low tens of thousands of E-Business Suite installations (subset with the Oracle Contracts module exposed via HTTP) — Internet-wide scans have historically shown on the order of thousands to tens of thousands of internet-reachable Oracle E-Business Suite web tiers globally, and only a subset of those run versions 12.2.14-12.2.15 with the Oracle Contracts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.