Junglewise Threat Intelligence

CVE-2026-83129: Oracle Sales privilege escalation in Oracle E-Business Suite

CVE-2026-83129 · Severity: high · CVSS 7.7 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Sales is a critical application within Oracle E-Business Suite used for managing customer orders and sales operations. This vulnerability allows a low-privileged user with network access to bypass controls and gain unauthorized access to sensitive customer data, potentially compromising confidentiality of the entire system and affecting downstream integrated business processes.

Technical details

This is an easily exploitable privilege escalation or authorization bypass vulnerability in the Internal Operations component of Oracle Sales. The vulnerability is accessible via HTTP from the network and requires only low-privileged credentials; no additional user interaction is needed. Successful exploitation allows attackers to read critical or complete datasets within Oracle Sales, though integrity and availability are not impacted. The scope change flag indicates that while the vulnerability resides in Oracle Sales, its exploitation can affect other Oracle E-Business Suite components that rely on Sales data.

Affected products

  • Oracle E-Business Suite Sales 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References