Junglewise Threat Intelligence

CVE-2026-83161: Oracle E-Business Suite Project Intelligence unauthorized data access

CVE-2026-83161 · Severity: high · CVSS 7.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Project Intelligence, a component of Oracle E-Business Suite used for project planning and management, contains a flaw that allows low-privileged attackers with network access to create, delete, or modify critical project data, or view sensitive project information. Successful exploitation could compromise project confidentiality and data integrity across the entire system.

Technical details

This is an authorization and data access control vulnerability in Oracle Project Intelligence (component: Internal Operations) that affects versions 12.2.3 through 12.2.15. The flaw is easily exploitable and requires only low-level privileges and network access via HTTP; no user interaction is needed. An authenticated attacker can exploit a logic flaw to gain unauthorized read access to subsets of Project Intelligence data and unauthorized create, delete, or modification access to critical data. The vulnerability results in both confidentiality and integrity compromise. Oracle has issued patches; users should update to patched versions within the 12.2.x branch or later.

Affected products

  • Oracle E-Business Suite Project Intelligence 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats