Junglewise Threat Intelligence

CVE-2026-83091: Oracle Field Service authentication bypass in E-Business Suite

CVE-2026-83091 · Severity: high · CVSS 7.6 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Field Service is a component of Oracle E-Business Suite that manages field operations and service requests. A network-accessible vulnerability allows an attacker with basic user privileges to gain unauthorized access to sensitive customer and operational data, modify critical records, or disrupt service availability. This could expose customer information, enable fraudulent transactions, or cause operational downtime.

Technical details

This is a low-complexity authentication or authorization bypass vulnerability in the Oracle Field Service component (Internal Operations) affecting versions 12.2.3 through 12.2.15. The vulnerability is network-reachable via HTTP and exploitable by low-privileged authenticated users without user interaction. Successful exploitation allows unauthorized disclosure of sensitive data, unauthorized modification or deletion of records, and partial denial of service. The vulnerability impacts confidentiality, integrity, and availability of the Field Service system. A fix is expected from Oracle as part of their September 2026 security update.

Affected products

  • Oracle Field Service 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed: Published via Oracle Critical Patch Update

References

Related threats