Junglewise Threat Intelligence

CVE-2026-83158: Oracle E-Business Suite Applications Manager privilege escalation in RapidClone

CVE-2026-83158 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite's Applications Manager tool includes a RapidClone command-line utility used for cloning and managing EBS environments. A privilege escalation vulnerability allows a low-privilege attacker with local system access to read, modify, or delete critical business data stored within the Applications Manager. Successful exploitation could lead to unauthorized access to sensitive application data and configuration information.

Technical details

This is a local privilege escalation vulnerability in the RapidClone component of Oracle E-Business Suite Applications Manager (versions 12.2.3–12.2.15). The vulnerability is easily exploitable and requires only local logon access to the infrastructure where the Applications Manager executes, with no special configuration or user interaction needed. An attacker with low-privilege credentials can achieve high-impact unauthorized access to read and modify critical data, and delete application data. The CVSS 3.1 score of 7.1 reflects local attack vector with high confidentiality and integrity impacts but no availability impact. Oracle has issued a security patch via its standard Critical Patch Update process.

Affected products

  • Oracle E-Business Suite 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats