Junglewise Threat Intelligence

CVE-2026-83112: Oracle Lease and Finance Management privilege escalation in E-Business Suite

CVE-2026-83112 · Severity: high · CVSS 7.2 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Lease and Finance Management is a component of Oracle E-Business Suite used to manage corporate lease agreements and financing operations. An attacker with high administrative privileges and network access can exploit a vulnerability to completely take over the system, potentially compromising financial records, lease data, and disrupting critical business operations.

Technical details

A privilege escalation vulnerability exists in Oracle Lease and Finance Management (component: Internal Operations) within Oracle E-Business Suite versions 12.2.7 through 12.2.15. The vulnerability is easily exploitable and requires high-privileged user access via HTTP network protocol. Successful exploitation allows an attacker to gain full control over the affected system, compromising confidentiality, integrity, and availability of stored financial and lease management data. Patches are available from Oracle as part of their September 2026 security updates.

Affected products

  • Oracle E-Business Suite Lease and Finance Management 12.2.7 through 12.2.15

Timeline

  • 2026-09-15: disclosed

References