Junglewise Threat Intelligence

CVE-2026-83127: Oracle Sales Offline data access bypass in E-Business Suite

CVE-2026-83127 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle Sales Offline is a component of Oracle's E-Business Suite that handles offline sales operations and data synchronization. A vulnerability allows a low-privileged user with network access to bypass authorization controls and access sensitive customer and operational data without proper permissions, potentially exposing confidential business information across multiple connected systems.

Technical details

This is an authorization bypass vulnerability in the Internal Operations component of Oracle Sales Offline. It is easily exploitable by a low-privileged attacker with network access via HTTP, requiring no user interaction. The vulnerability has a scope change indicator, meaning exploitation can impact other Oracle E-Business Suite products beyond Sales Offline itself. Successful attacks result in unauthorized read access to critical data—an attacker can view all data accessible by the vulnerable component. The CVSS 3.1 score is 7.7 (Network, Low Complexity, Low Privilege required, Scope Changed, High Confidentiality impact).

Affected products

  • Oracle E-Business Suite 12.2.3 to 12.2.15 (Sales Offline component)

Timeline

  • 2026-09-15: disclosed

References

Related threats