Junglewise Threat Intelligence

CVE-2026-83162: Oracle Application Object Library unauthenticated data modification vulnerability

CVE-2026-83162 · Severity: high · CVSS 7.4 · Published 2026-09-15

Technologies: Oracle E-Business Suite Application Object Library. Vendors: Oracle.

Executive brief

The Oracle Application Object Library is a core component of Oracle E-Business Suite that manages business data and application functions. An unauthenticated attacker on the network can exploit a vulnerability in this component to read, create, modify, or delete critical business data without proper authorization. This could lead to data corruption, unauthorized business transactions, or exposure of sensitive information.

Technical details

This is an unauthenticated vulnerability in Oracle Application Object Library (component of Oracle E-Business Suite) accessible via HTTPS. The vulnerability allows remote attackers with network access to read and modify critical data or all accessible data in the library without authentication. The attack is difficult to exploit and requires specific conditions to succeed. Affected versions are 12.2.3 through 12.2.15. A patch from Oracle is expected; check Oracle's security advisories for mitigation details.

Affected products

  • Oracle E-Business Suite Application Object Library 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats