Junglewise Threat Intelligence

CVE-2026-83125: Oracle E-Business Suite Report Manager remote compromise via HTTP

CVE-2026-83125 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite Report Manager is a critical business reporting component used by enterprises to generate financial and operational reports. A network-accessible vulnerability allows a low-privileged user to gain complete control of the Report Manager, potentially compromising sensitive business data, disrupting report generation, and affecting financial operations and compliance.

Technical details

This vulnerability in Oracle E-Business Suite Report Manager (component: Internal Operations) allows remote code execution or system compromise via HTTP. The flaw is easily exploitable by a low-privileged attacker with network access; no special user interaction is required. Successful exploitation results in complete takeover of the Report Manager process, leading to confidentiality, integrity, and availability compromise. Affected versions are 12.2.3 through 12.2.15. Oracle has published security guidance; patched versions are available through official channels.

Affected products

  • Oracle E-Business Suite 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats