Junglewise Threat Intelligence

CVE-2026-83080: Oracle Banking Branch privilege escalation in Reports

CVE-2026-83080 · Severity: high · CVSS 7.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Banking Branch is a core component of Oracle Financial Services Applications used to manage branch operations and reporting. A vulnerability in the Reports module allows a low-privileged user with network access to gain complete control over the application through a crafted request that requires user interaction. Successful exploitation could lead to unauthorized access to sensitive banking data, system compromise, and service disruption.

Technical details

This is a difficult-to-exploit vulnerability affecting the Reports component of Oracle Banking Branch versions 14.5.0.0.0 through 14.9.0.0.0. The vulnerability requires low privilege access and network connectivity via HTTP, along with social engineering or user interaction from another user. The attack vector is network-based with high complexity (AC:H) and requires user interaction (UI:R). Successful exploitation results in complete system compromise with high impact to confidentiality, integrity, and availability. The vulnerability allows an attacker to achieve privilege escalation and takeover of the Oracle Banking Branch application. Patch status and fix details are not yet confirmed in available sources.

Affected products

  • Oracle Banking Branch 14.5.0.0.0 to 14.9.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats