ZeroHour

CVE-2026-83486

moderate

Authenticated Data Exposure in Oracle Product Hub (E-Business Suite Item Catalog)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83486 is a high-severity (CVSS 7.7) vulnerability in the Item Catalog component of Oracle Product Hub, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can easily exploit the flaw to gain unauthorized access to critical data, up to complete access to all Oracle Product Hub accessible data. The vulnerability has a scope change, meaning successful attacks may also significantly impact additional products beyond Oracle Product Hub itself, though the impact is limited to confidentiality (no integrity or availability impact). Affected organizations are enterprises running affected 12.2.x releases of Oracle E-Business Suite with Product Hub exposed to users over HTTP. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation is currently unknown.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83486 to all E-Business Suite 12.2.3-12.2.15 environments running Oracle Product Hub. Restrict HTTP access to EBS endpoints so only authenticated, authorized business users and internal networks can reach the Item Catalog functionality. Review audit and access logs for unusual data retrieval by low-privileged accounts, given the flaw exposes critical data with no integrity or availability footprint to detect.

Affected
Oracle E-Business Suite (Oracle Product Hub, Item Catalog component)12.2.3-12.2.15
Estimated exposure
moderatethousands of internet-exposed E-Business Suite instances; tens of thousands of total EBS deployments worldwide — Internet-wide scans (Shodan/Censys) typically show a few thousand Oracle E-Business Suite web endpoints exposed to the internet, with a substantially larger install base of 12.2.x deployments running on internal networks, only a subset of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. While the vulnerability is in Oracle Product Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.