CVE-2026-83485
moderateAuthenticated Data Exposure in Oracle E-Business Suite Product Hub (Item Catalog)
CVE-2026-83485 is an information-disclosure flaw in the Item Catalog component of Oracle Product Hub, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP — for example, any authenticated EBS user with minimal privileges — can easily exploit the flaw to gain unauthorized access to critical data or complete access to all data reachable through Oracle Product Hub. Because of a scope change, successful attacks may also significantly impact additional Oracle E-Business Suite products beyond Product Hub itself. The vulnerability carries a CVSS 3.1 base score of 7.7 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), with high confidentiality impact but no integrity or availability impact. There is no known public proof of concept and the flaw is not on the CISA KEV list, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83485 to all E-Business Suite 12.2.3-12.2.15 environments running Product Hub, prioritizing instances with HTTP endpoints reachable from untrusted networks. Restrict access to EBS self-service and Product Hub pages so only necessary authenticated users can reach the Item Catalog functionality, and enforce least-privilege roles for low-privileged accounts. Review audit logs for unusual data retrieval by low-privilege users against Product Hub and related modules to rule out prior exploitation.
| Oracle E-Business Suite Product Hub (Item Catalog component) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. While the vulnerability is in Oracle Product Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.