Junglewise Threat Intelligence

CVE-2026-83132: Oracle iStore privilege escalation in Shopping Cart

CVE-2026-83132 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle E-Business Suite iStore. Vendors: Oracle.

Executive brief

Oracle iStore is an e-commerce shopping cart component within Oracle E-Business Suite used to manage online ordering and catalog management. A vulnerability allows a low-privileged attacker to gain unauthorized access to, create, delete, or modify critical business data within the shopping cart system, potentially exposing customer information and order data.

Technical details

This is a privilege escalation vulnerability in the Oracle iStore Shopping Cart component affecting versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP. No user interaction or high privileges are required. Successful exploitation allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all iStore-accessible data. The CVSS 3.1 score of 8.1 reflects high confidentiality and integrity impacts with no availability impact.

Affected products

  • Oracle E-Business Suite iStore 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats