ZeroHour

CVE-2026-83489

niche

Low-Privilege Takeover Flaw in Oracle Banking Origination 14.5-14.9 Onboarding Batch Processes

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83489 is a difficult-to-exploit vulnerability in the Onboarding Batch Processes component of Oracle Banking Origination, part of Oracle's Financial Services Applications suite. A remote attacker who already holds low-privileged credentials and has HTTP network access to the application can exploit the flaw, and a successful attack results in a full takeover of the Oracle Banking Origination system, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). Affected deployments are versions 14.5.0.0.0 through 14.9.0.0.0, which are primarily installed at banks and other financial institutions running Oracle's loan origination/onboarding platform. The requirement for prior low-privileged access and the high attack complexity make opportunistic exploitation less likely, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. No public proof-of-concept or observed in-the-wild exploitation is known at this time.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83489 to all Oracle Banking Origination 14.5.0.0.0-14.9.0.0.0 instances as soon as patching windows allow. In the interim, restrict HTTP access to the Onboarding Batch Processes endpoints to trusted internal networks and authenticated users, and enforce least privilege so low-privileged accounts cannot reach sensitive batch functions. Review application and audit logs for anomalous activity by low-privileged accounts against onboarding batch jobs to rule out any compromise attempts.

Affected
Oracle Banking Origination (Oracle Financial Services Applications), Onboarding Batch Processes component14.5.0.0.0 - 14.9.0.0.0
Estimated exposure
nicheunknown; plausibly on the order of hundreds to a few thousand bank/financial-institution installations worldwide — Oracle Banking Origination is licensed enterprise banking software deployed per-institution rather than distributed at scale, and no public active-install counts or internet-exposure scans specific to this product are available, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Onboarding Batch Processes). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks of this vulnerability can result in takeover of Oracle Banking Origination. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.