CVE-2026-83490
moderateAuthenticated data-access flaw in Oracle iRecruitment (EBS 12.2.3-12.2.15)
A high-severity (CVSS 3.1: 8.5) vulnerability in the Internal Operations component of Oracle iRecruitment, part of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the module. The flaw is easily exploitable and is triggered by an authenticated user sending requests to affected iRecruitment web endpoints, without needing user interaction. A successful attack yields unauthorized read access to critical data — or complete access to all data reachable through Oracle iRecruitment, such as candidate and HR recruitment records — as well as unauthorized insert, update, or delete capability over some of that data; because of a scope change, impact may extend to additional E-Business Suite products beyond iRecruitment itself. All organizations running Oracle iRecruitment on E-Business Suite versions 12.2.3 through 12.2.15 are affected. There is no known public proof of concept, the issue is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported; a fix is available through Oracle's Critical Patch Update program.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83490 to all E-Business Suite 12.2.3-12.2.15 environments running iRecruitment, prioritizing any instance reachable from the internet. Restrict HTTP access to iRecruitment/EBS self-service endpoints to trusted networks or VPN, and enforce least-privilege on internal user accounts since exploitation requires only low-privileged credentials. Review audit logs for anomalous reads or modifications of recruitment/HR data by low-privilege accounts to rule out prior exploitation.
| Oracle iRecruitment (Oracle E-Business Suite, component: Internal Operations) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment. While the vulnerability is in Oracle iRecruitment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data as well as unauthorized update, insert or delete access to some of Oracle iRecruitment accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.