Junglewise Threat Intelligence

CVE-2026-83114: Oracle Quality privilege escalation in Oracle E-Business Suite

CVE-2026-83114 · Severity: high · CVSS 7.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Quality is a quality management module within Oracle's E-Business Suite used for managing product quality and manufacturing operations. A vulnerability in this component allows a low-privileged network user to gain complete control over the Quality system, potentially compromising critical quality and operational data, disrupting manufacturing workflows, and enabling tampering with quality records.

Technical details

This is a privilege escalation vulnerability in the Oracle Quality component of Oracle E-Business Suite affecting versions 12.2.3 through 12.2.15. The vulnerability requires low privilege credentials and network access via HTTP, but is difficult to exploit (high complexity). An authenticated attacker can leverage this flaw to escalate privileges and achieve full compromise of the Oracle Quality system, impacting confidentiality, integrity, and availability of quality management functions. Oracle has released patches as part of their September 2026 security update.

Affected products

  • Oracle E-Business Suite Quality 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed: CVE-2026-83114 published

References

Related threats