Junglewise Threat Intelligence

CVE-2026-83117: Oracle E-Business Suite Applications DBA privilege escalation

CVE-2026-83117 · Severity: high · CVSS 7.2 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite is a comprehensive enterprise resource planning (ERP) platform used to manage business operations across finance, supply chain, and human resources. A vulnerability in the Applications DBA component allows high-privileged network users to take complete control of the DBA system, potentially compromising sensitive business data and operational continuity. This represents a critical risk for organizations relying on E-Business Suite for core business processes.

Technical details

The vulnerability exists in the AD Utilities component of Oracle E-Business Suite's Applications DBA product (versions 12.2.3 through 12.2.15) and is classified as an easily exploitable privilege escalation flaw. An attacker with high administrative privileges and network access via HTTP can exploit this vulnerability without user interaction to achieve complete takeover of the Applications DBA system. The vulnerability allows compromise of confidentiality, integrity, and availability of the affected component. A patch or security update from Oracle is likely required to remediate this issue.

Affected products

  • Oracle E-Business Suite 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats