Junglewise Threat Intelligence

CVE-2026-83136: Oracle E-Business Suite Spares Management privilege escalation via HTTP

CVE-2026-83136 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle E-Business Suite Spares Management. Vendors: Oracle.

Executive brief

Oracle Spares Management is a module of E-Business Suite used for inventory and procurement operations. A network-accessible vulnerability allows a low-privileged user to gain complete control over the Spares Management system, potentially exposing or manipulating critical supply chain and inventory data. Attackers can trigger the exploit remotely with minimal authentication, putting organizations at risk of operational disruption and data compromise.

Technical details

The vulnerability exists in the Internal Operations component of Oracle E-Business Suite Spares Management (versions 12.2.3 through 12.2.15) and is exploitable via HTTP by a low-privileged attacker with network access. The flaw allows an authenticated user to elevate privileges and achieve complete system compromise, affecting confidentiality, integrity, and availability. No user interaction is required; the attack is straightforward to execute due to low access complexity. The vulnerability has not been observed in active exploitation as of the publication date, but patches or mitigations from Oracle are recommended.

Affected products

  • Oracle E-Business Suite Spares Management 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats