Junglewise Threat Intelligence

CVE-2026-83121: Oracle E-Business Suite Marketing privilege escalation in Audience component

CVE-2026-83121 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle E-Business Suite Marketing. Vendors: Oracle.

Executive brief

A vulnerability in Oracle E-Business Suite's Marketing module (Audience component) allows a low-privileged attacker with network access to gain complete control over the marketing system. An attacker with basic user credentials can exploit this flaw via HTTP to compromise confidentiality, integrity, and availability of the marketing application, potentially leading to unauthorized access to customer data and campaign sabotage.

Technical details

This is an easily exploitable privilege escalation vulnerability in the Audience component of Oracle E-Business Suite's Marketing product. The flaw requires low-level privileges and network access via HTTP; no user interaction is needed. An attacker authenticated to the system can leverage the vulnerability to escalate privileges and achieve complete takeover of the Oracle Marketing application, affecting confidentiality, integrity, and availability. Affected versions are 12.2.3 through 12.2.15. Patch availability through Oracle's security updates should be verified at oracle.com/security-alerts.

Affected products

  • Oracle E-Business Suite Marketing 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats