Junglewise Threat Intelligence

CVE-2026-83116: Oracle Order Management information disclosure in Product Diagnostic Tools

CVE-2026-83116 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle E-Business Suite Order Management. Vendors: Oracle.

Executive brief

Oracle Order Management, a critical component of Oracle E-Business Suite used by enterprises to manage sales orders and fulfillment, contains a flaw in its Product Diagnostic Tools component. An attacker with basic network access and low-level system privileges can exploit this vulnerability to access sensitive business data, including order information, customer details, and other confidential order management records. The vulnerability could also impact other connected Oracle E-Business Suite components.

Technical details

This is an information disclosure vulnerability in the Product Diagnostic Tools component of Oracle Order Management. The vulnerability is easily exploitable and requires a network attacker with low privilege credentials and HTTP access, but does not require user interaction. Successful exploitation allows unauthorized access to critical data or complete access to all Oracle Order Management accessible data. The CVSS 3.1 score of 7.7 reflects high confidentiality impact with changed scope, indicating potential broader system compromise. Affected versions are Oracle E-Business Suite 12.2.5 through 12.2.15; patches are expected from Oracle's security advisory (CSP Update September 2026).

Affected products

  • Oracle E-Business Suite Order Management 12.2.5 through 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats