Junglewise Threat Intelligence

CVE-2026-83135: Oracle iStore privilege escalation in Shopping Cart

CVE-2026-83135 · Severity: high · CVSS 8.7 · Published 2026-09-15

Technologies: Oracle E-Business Suite iStore. Vendors: Oracle.

Executive brief

Oracle iStore is the e-commerce component of Oracle E-Business Suite used to power online stores and shopping functionality. A vulnerability in the Shopping Cart allows a low-privileged authenticated attacker to manipulate critical business data—including unauthorized creation, deletion, or modification of orders, products, or customer records—and access confidential information. The attack requires tricking another user into performing an action, but the impact extends beyond iStore to potentially compromise other E-Business Suite modules.

Technical details

This is a privilege escalation vulnerability in the Oracle iStore Shopping Cart component affecting versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable via HTTP and requires a low-privileged user account plus user interaction (likely CSRF or similar social engineering vector). The root cause involves insufficient access controls or authorization checks in the Shopping Cart, permitting authenticated users to perform unauthorized operations on critical data. Successful exploitation allows reading, creating, modifying, or deleting Oracle iStore data and potentially impacting connected E-Business Suite systems due to scope change. Oracle has released patches; users should apply updates for their supported version immediately.

Affected products

  • Oracle E-Business Suite iStore 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats