Junglewise Threat Intelligence

CVE-2026-83113: Oracle Quality privilege escalation in E-Business Suite

CVE-2026-83113 · Severity: high · CVSS 7.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Quality is a module within Oracle's E-Business Suite used for managing product quality processes and inspection workflows. A vulnerability in the Internal Operations component allows a low-privileged employee with network access to bypass access controls and read sensitive quality data or make unauthorized changes to quality records, potentially compromising product compliance and audit trails.

Technical details

This is a privilege escalation vulnerability in Oracle Quality's Internal Operations component affecting E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable by a low-privileged, authenticated user over HTTP with no user interaction required. The root cause appears to involve insufficient access controls on business operations. Successful exploitation grants unauthorized read access to confidential quality data and limited write access (update/insert/delete) to quality records. A patch is expected in Oracle's September 2026 security update.

Affected products

  • Oracle E-Business Suite Quality 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats