Junglewise Threat Intelligence

CVE-2026-83152: Oracle Project Intelligence unauthorized data access in E-Business Suite

CVE-2026-83152 · Severity: high · CVSS 8.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Project Intelligence is a component of Oracle's E-Business Suite used for project planning and tracking. A low-privileged attacker with network access can exploit this vulnerability to read, create, delete, or modify sensitive project data without authorization, compromising both the confidentiality and integrity of critical business information.

Technical details

This vulnerability in Oracle E-Business Suite's Project Intelligence component (Internal Operations) allows a low-privileged, authenticated attacker to perform unauthorized data operations via HTTP without requiring user interaction. The vulnerability affects versions 12.2.3 through 12.2.15 and permits attackers to read, create, delete, or modify critical project data beyond their authorization level. The attack requires network access and an existing low-privileged account but does not require administrator privileges or additional interaction. High impact to both confidentiality and integrity of accessible data has been confirmed, with no availability impact reported. Patch availability should be verified through Oracle's official security advisory.

Affected products

  • Oracle E-Business Suite Project Intelligence 12.2.3 through 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats