CVE-2026-83486
moderateAuthenticated Data Exposure in Oracle Product Hub (E-Business Suite Item Catalog)
CVE-2026-83486 is a high-severity (CVSS 7.7) vulnerability in the Item Catalog component of Oracle Product Hub, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can easily exploit the flaw to gain unauthorized access to critical data, up to complete access to all Oracle Product Hub accessible data. The vulnerability has a scope change, meaning successful attacks may also significantly impact additional products beyond Oracle Product Hub itself, though the impact is limited to confidentiality (no integrity or availability impact). Affected organizations are enterprises running affected 12.2.x releases of Oracle E-Business Suite with Product Hub exposed to users over HTTP. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation is currently unknown.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83486 to all E-Business Suite 12.2.3-12.2.15 environments running Oracle Product Hub. Restrict HTTP access to EBS endpoints so only authenticated, authorized business users and internal networks can reach the Item Catalog functionality. Review audit and access logs for unusual data retrieval by low-privileged accounts, given the flaw exposes critical data with no integrity or availability footprint to detect.
| Oracle E-Business Suite (Oracle Product Hub, Item Catalog component) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. While the vulnerability is in Oracle Product Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.