Junglewise Threat Intelligence

CVE-2026-83138: Oracle E-Business Suite Spares Management privilege escalation in Internal Operations

CVE-2026-83138 · Severity: high · CVSS 8 · Published 2026-09-15

Technologies: Oracle E-Business Suite Spares Management. Vendors: Oracle.

Executive brief

Oracle Spares Management is a component of Oracle E-Business Suite used to manage spare parts inventory and operations. A difficult-to-exploit vulnerability allows a privileged network attacker to gain complete control over the system, and the attack can cascade to compromise other connected business applications. This could lead to loss of operational visibility, data integrity issues across critical supply chain systems, and potential business disruption.

Technical details

This is a privilege escalation vulnerability in the Oracle Spares Management product (Internal Operations component) affecting versions 12.2.3 through 12.2.15. The vulnerability requires a high-privileged attacker with network access via HTTP; it is difficult to exploit and results in scope change, meaning successful exploitation can impact systems beyond the directly vulnerable component. A successful attack grants complete takeover of Oracle Spares Management with confidentiality, integrity, and availability impacts.

Affected products

  • Oracle E-Business Suite Spares Management 12.2.3 through 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats