ZeroHour

CVE-2026-83483

moderate

Privileged-Takeover Flaw in Oracle Advanced Benefits Self-Service (EBS 12.2)

CVSS 3.1
8.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83483 is a high-severity vulnerability (CVSS 3.1: 8.0) in the Self-Service What-if Analysis component of Oracle Advanced Benefits, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is triggered by a high-privileged attacker with network access via HTTP, and while rated difficult to exploit, successful attacks result in a full takeover of Oracle Advanced Benefits — complete compromise of confidentiality, integrity, and availability. The CVSS scope-change rating (S:C) means exploitation can also significantly impact additional Oracle E-Business Suite products beyond the vulnerable component. Affected organizations are enterprises running affected EBS 12.2.x releases with the Advanced Benefits HR module deployed. There is no known public proof-of-concept, no known in-the-wild exploitation, and the flaw is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83483 to all E-Business Suite 12.2.3-12.2.15 environments running Advanced Benefits. Because exploitation requires a high-privileged HTTP session, restrict access to Self-Service What-if Analysis pages, enforce least-privilege role assignments for HR/benefits administrators, and place EBS behind VPN or IP allowlisting rather than exposing it directly to the internet. Review HTTP access logs for anomalous activity from high-privileged accounts against Advanced Benefits self-service pages to rule out prior compromise.

Affected
Oracle Advanced Benefits (Oracle E-Business Suite, component: Self-Service What-if Analysis)12.2.3-12.2.15
Estimated exposure
moderatelikely low-thousands of installations (subset of E-Business Suite deployments with the Advanced Benefits module) — Oracle E-Business Suite is deployed at thousands of organizations worldwide with a few thousand internet-reachable instances visible in public scans, and Advanced Benefits is a narrower HR self-service module within that base; no official…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. While the vulnerability is in Oracle Advanced Benefits, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Advanced Benefits. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.