Junglewise Threat Intelligence

CVE-2026-83126: Oracle Sales Online privilege escalation and data access vulnerability

CVE-2026-83126 · Severity: high · CVSS 7.6 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Sales Online, a component of Oracle E-Business Suite used for managing sales operations, contains a vulnerability that allows a low-privileged user with network access to gain unauthorized access to sensitive business data or modify critical information. The attack requires user interaction from another party and may impact other connected enterprise systems, potentially compromising customer data or sales records.

Technical details

This is a low-complexity network-accessible vulnerability in Oracle Sales Online's Internal Operations component affecting versions 12.2.3 through 12.2.15. The vulnerability allows a low-privileged attacker to escalate access via HTTP, with scope change indicating that successful exploitation may affect other Oracle E-Business Suite products. User interaction is required from a different user. Successful exploitation results in unauthorized confidentiality breach (complete read access to Oracle Sales Online data) and integrity impact (unauthorized create, update, or delete operations on some data). Patches are expected to be available through Oracle's security patch cycle.

Affected products

  • Oracle Sales Online 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats