Junglewise Threat Intelligence

CVE-2026-83110: Oracle Marketing unauthenticated data access in E-Business Suite

CVE-2026-83110 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite's Marketing module contains a flaw that allows unauthenticated attackers to access critical business data over the network. An attacker can exploit this vulnerability without any credentials or user interaction, potentially exposing sensitive customer information, campaign data, and audience details managed within the marketing system.

Technical details

The vulnerability exists in the Audience component of Oracle E-Business Suite's Marketing product (versions 12.2.3–12.2.15) and allows unauthenticated attackers with network access via HTTP to gain unauthorized access to sensitive data. The vulnerability is classified as an information disclosure issue with high confidentiality impact (CVSS 3.1 score 7.5). The attack requires no authentication, low complexity, and no user interaction, making it easily exploitable. Successful exploitation grants attackers complete access to all data accessible through the Oracle Marketing module. Patches are expected from Oracle's security updates.

Affected products

  • Oracle E-Business Suite 12.2.3–12.2.15 (Marketing product, Audience component)

Timeline

  • 2026-09-15: disclosed

References

Related threats