Junglewise Threat Intelligence

CVE-2026-83165: Oracle Customer Interaction History privilege escalation in Oracle E-Business Suite

CVE-2026-83165 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle E-Business Suite Customer Interaction History. Vendors: Oracle.

Executive brief

Oracle Customer Interaction History is a module of Oracle E-Business Suite used to store and manage customer interactions and transaction records. A vulnerability in the user interface allows a low-privileged internal user with network access to gain full control over the system, potentially exposing or modifying sensitive customer data and business records.

Technical details

This is a privilege escalation vulnerability in the Oracle Customer Interaction History user interface component, affecting versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable and requires network access via HTTPS and a low-privilege user account (no high-privilege credentials needed). An authenticated attacker can exploit this flaw to achieve full system compromise with confidentiality, integrity, and availability impacts. Oracle has released a security patch as part of its standard security update cycle.

Affected products

  • Oracle E-Business Suite Customer Interaction History 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats