Junglewise Threat Intelligence

CVE-2026-83118: Oracle E-Business Suite Applications DBA privilege escalation in AD Utilities

CVE-2026-83118 · Severity: high · CVSS 7.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle E-Business Suite is a suite of enterprise resource planning (ERP) applications used to manage business operations and customer relations. The Applications DBA component, specifically the AD Utilities module, contains a privilege escalation vulnerability that allows a low-privileged user with local system access to gain full control over the Applications DBA system. A successful attack could compromise sensitive financial, operational, and customer data stored within the ERP system.

Technical details

The vulnerability is a privilege escalation flaw in the AD Utilities component of Oracle E-Business Suite's Applications DBA product, affecting versions 12.2.3 through 12.2.15. The attack vector is local; an attacker must have low-privilege logon access to the infrastructure where Applications DBA executes (AC:L, PR:L, AV:L). No user interaction is required. Successful exploitation allows the attacker to achieve complete takeover of the Applications DBA system with high impacts to confidentiality, integrity, and availability. The vulnerability is easily exploitable and a patch is expected from Oracle's security update process.

Affected products

  • Oracle E-Business Suite Applications DBA 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References