Low-Privilege Takeover Flaw in Oracle BI Enterprise Edition 12.2.1.4.0
CVE-2026-83282 is a critical vulnerability (CVSS 3.1 base score 9.9) in the Platform Security component of Oracle Business Intelligence Enterprise Edition 12.2.1.4.0, part of Oracle Analytics. A low-privileged, authenticated attacker with network access via HTTP can send crafted requests that compromise the OBIEE installation and, because the scope changes, may also significantly impact additional products beyond OBIEE itself. Successful exploitation results in a complete takeover of OBIEE with high impact on confidentiality, integrity, and availability, meaning an attacker could read, alter, or destroy business analytics data and pivot to connected systems. Organizations running the affected 12.2.1.4.0 release, especially instances reachable over a network, are at risk. As of now, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and no active exploitation has been reported.
· Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Platform Security)moderate
Unauthenticated Takeover Flaw in Oracle EBS Document Management and Collaboration
CVE-2026-83452 is a critical (CVSS 9.8) flaw in the Internal Operations component of the Oracle Document Management and Collaboration product within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks allow complete takeover of the Document Management and Collaboration component with high impact to confidentiality, integrity, and availability. Organizations running affected EBS releases that expose these services to a network — especially internet-facing HTTP endpoints — are at risk of full compromise of sensitive documents and collaboration data. The flaw is addressed in Oracle's Critical Patch Update cycle, but the specific flaw type (e.g., injection or deserialization) was not disclosed by Oracle. No public proof-of-concept or confirmed in-the-wild exploitation has been reported, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.
· Oracle E-Business Suite - Oracle Document Management and Collaboration (Internal Operations component) 12.2.3-12.2.15moderate
Unauthenticated Takeover Flaw in Oracle BI Enterprise Edition 12.2.1.4.0
CVE-2026-83283 is a critical (CVSS 9.8) flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), affecting version 12.2.1.4.0. It is triggered remotely over HTTP by an attacker with no credentials and no user interaction, requiring only network reachability to the OBIEE service. A successful exploit allows complete takeover of the OBIEE installation, with high impact on confidentiality, integrity, and availability — including access to sensitive analytics data, reports, and potentially connected backend data sources. Organizations running the affected 12.2.1.4.0 release, especially those with OBIEE consoles reachable from untrusted networks, are at risk. There is no known public proof of concept and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
· Oracle Business Intelligence Enterprise Edition (Oracle Analytics) 12.2.1.4.0moderate
Unauthenticated Remote Takeover in Oracle BI Publisher (BI Platform Security)
Oracle BI Publisher, part of Oracle Analytics, contains an easily exploitable flaw in its BI Platform Security component that lets an unauthenticated attacker with HTTP network access compromise the application. Successful attacks result in a complete takeover of Oracle BI Publisher, with high impacts to confidentiality, integrity, and availability, reflected in a CVSS 3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N). Affected deployments include versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0, spanning legacy on-premises OBIEE-era releases through the current analytics release. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, but the unauthenticated, network-reachable nature makes internet-facing consoles a high-priority patch target.
· Oracle BI Publisher (Oracle Analytics, component: BI Platform Security)moderate
Unauthenticated SOAP Flaw in Oracle E-Business Suite Framework Allows Full Takeover
CVE-2026-83327 is a critical vulnerability (CVSS 9.8) in the Personalization component of Oracle Applications Framework within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker who has network access to the target via SOAP, requiring no privileges or user interaction. A successful attack allows the attacker to compromise Oracle Applications Framework and take it over, with high impact on the confidentiality, integrity, and availability of the affected system. Any organization running E-Business Suite Release 12.2 in the affected version range is potentially exposed, particularly instances with SOAP endpoints reachable from untrusted networks. There is no known public proof-of-concept, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported as of this writing.
· Oracle E-Business Suite (Oracle Applications Framework, Personalization component) 12.2.3-12.2.15moderate
Unauthenticated Takeover in Oracle EBS Mobile Application Server (MWA Terminal Server)
CVE-2026-83462 is a critical (CVSS 9.8) vulnerability in the MWA Terminal Server component of the Oracle Mobile Application Server, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. An unauthenticated remote attacker who can reach the MWA Terminal Server's TCP port over the network can exploit the flaw without any user interaction or credentials, and a successful attack results in a complete takeover of the Oracle Mobile Application Server with high impact to confidentiality, integrity, and availability. Because exploitation is described as easy and requires no privileges, any EBS environment running an affected version with the MWA service reachable (especially from the internet) is at serious risk of full server compromise. Organizations running EBS 12.2.3-12.2.15 in warehouse, manufacturing, or mobile data-collection deployments are the primary affected population. There is no known public proof-of-concept and the flaw is not on the CISA KEV list, so exploitation status is currently none known.
· Oracle E-Business Suite - Oracle Mobile Application Server (MWA Terminal Server component) 12.2.3-12.2.15moderate
Unauthenticated SOAP Data Access Flaw in Oracle Siebel CRM Open UI
CVE-2026-83154 is a critical (CVSS 9.1) vulnerability in the Open UI component of Oracle Siebel CRM's End User product, affecting all supported versions from 17.0 through 26.7. It is easily exploitable by an unauthenticated attacker with network access who can reach the product's SOAP interface, requiring no privileges or user interaction. A successful attack lets the attacker create, delete, or modify critical data — or all data accessible to the Siebel CRM End User application — as well as read that data in full, with high impacts on both confidentiality and integrity (availability is not affected). Any organization running Siebel CRM within the affected version range with a network-reachable SOAP endpoint is exposed, particularly if the service is internet-facing. The flaw is not currently listed in CISA's KEV catalog, no public proof-of-concept is known, and no exploitation in the wild has been reported.
· Oracle Siebel CRM (End User product, Open UI component) 17.0-26.7moderate
High-Privilege Takeover Flaw in Oracle BI Publisher (BI Platform Security)
CVE-2026-83268 is a critical (CVSS 9.1) vulnerability in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics, affecting versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. It is easily exploitable by an already high-privileged, authenticated attacker who has network access to the BI Publisher HTTP interface, so the practical risk is privilege escalation and full product takeover from an administrative foothold rather than an anonymous internet attack. Successful exploitation results in complete compromise of confidentiality, integrity and availability of Oracle BI Publisher, and because the vulnerability has a scope change (S:C), attacks may also significantly impact additional products beyond BI Publisher itself. Organizations running any of the three listed versions, whether on-premises or in Oracle Cloud, are affected. No public proof-of-concept exists and the flaw is not currently listed in CISA's Known Exploited Vulnerabilities catalog.
· Oracle BI Publisher (Oracle Analytics, component: BI Platform Security) 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0moderate
Unauthenticated Data Exposure & DoS in Oracle Siebel CRM Financial Services
CVE-2026-83197 is a critical (CVSS 9.1) flaw in the Financial Accounts component of Oracle Siebel Apps - Financial Services, affecting all supported versions from 17.0 through 26.7. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack allows the attacker to read critical data — up to complete access to all data accessible through Siebel Apps - Financial Services — and to cause a hang or frequently repeatable crash, resulting in complete denial of service. Integrity impact is rated as none, so the flaw is primarily a confidentiality and availability risk rather than code execution. No public proof-of-concept exists and the vulnerability is not on the CISA KEV list, so exploitation in the wild is not currently known.
· Oracle Siebel Apps - Financial Services (Oracle Siebel CRM, component: Financial Accounts) 17.0-26.7moderate
Privileged HTTP Takeover Flaw in Oracle Siebel CRM Deployment (Server Infrastructure)
CVE-2026-83196 is a critical (CVSS 9.1) vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM, specifically in the Server Infrastructure component, affecting supported versions 17.0 through 26.7. It is remotely exploitable over HTTP but requires a high-privileged attacker (such as an administrator with valid credentials), which lowers the realistic attack surface to insider threats, compromised admin accounts, or credential-theft-driven attacks. Because the vulnerability has a scope change (S:C), successful exploitation can significantly impact products beyond Siebel CRM Deployment, and a successful attack results in complete takeover of the Siebel CRM Deployment component with high impact to confidentiality, integrity, and availability. Organizations running affected Siebel CRM versions are exposed, particularly if the deployment/management interfaces are reachable over the network. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so no active exploitation is known.
· Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component) 17.0 - 26.7moderate