Junglewise Threat Intelligence

CVE-2026-83164: Oracle E-Business Suite Customer Interaction History privilege escalation

CVE-2026-83164 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle Customer Interaction History is a component within Oracle's E-Business Suite that stores customer communications and transaction records. A low-privileged attacker with network access can exploit this vulnerability to gain full control of the system, potentially compromising sensitive customer interaction data and disrupting business operations.

Technical details

This is an easily exploitable vulnerability in the Outcome-Result component of Oracle Customer Interaction History that allows a low-privileged attacker with network access via HTTP to achieve complete system compromise. The vulnerability enables unauthorized access and control over the affected application through a network-accessible interface without requiring user interaction. Successful exploitation results in full compromise of confidentiality, integrity, and availability of the Customer Interaction History service. The vulnerability affects versions 12.2.3 through 12.2.15 of Oracle E-Business Suite; patches should be available through Oracle's standard security update channels.

Affected products

  • Oracle E-Business Suite 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats