Junglewise Threat Intelligence

CVE-2026-83159: Oracle E-Business Suite Applications DBA privilege escalation in ADPatch

CVE-2026-83159 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite is a widely deployed enterprise resource planning (ERP) system that manages critical business operations including finance, supply chain, and human resources. A local privilege escalation vulnerability in the ADPatch component allows an unauthenticated attacker with local system access to gain full control of the Applications DBA service through a mechanism requiring user interaction. Successful exploitation could enable complete takeover of the ERP system's database administration functionality, compromising confidentiality, integrity, and availability of business-critical data.

Technical details

This is a local privilege escalation vulnerability in the ADPatch component of Oracle E-Business Suite Applications DBA module. The vulnerability allows an unauthenticated attacker with local logon access to the infrastructure to achieve full compromise of the Applications DBA service. The attack is easily exploitable but requires human interaction from another user (e.g., social engineering or tricking a privileged user into executing code). Successful exploitation results in full takeover of Applications DBA with high impact to confidentiality, integrity, and availability. The vulnerability affects versions 12.2.3 through 12.2.15. Patches are expected to be available through Oracle's regular security update channels.

Affected products

  • Oracle E-Business Suite 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats