Junglewise Threat Intelligence

CVE-2026-83166: Oracle Customer Interaction History unauthorized data access in E-Business Suite

CVE-2026-83166 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle E-Business Suite Customer Interaction History. Vendors: Oracle.

Executive brief

Oracle Customer Interaction History is a data management component within Oracle E-Business Suite used to store and retrieve customer interaction records. A network-accessible vulnerability allows low-privileged users to read sensitive customer data without authorization, potentially exposing confidential business information and customer records across the entire system.

Technical details

This is an unauthorized data access vulnerability in the Outcome-Result component of Oracle Customer Interaction History. The vulnerability is easily exploitable over HTTP by an authenticated attacker with low privilege level and network access, requiring no user interaction. Successful exploitation results in unauthorized read access to critical customer interaction data, with a scope change indicating potential impact to other connected Oracle E-Business Suite products. The vulnerability affects versions 12.2.3 through 12.2.15 of Oracle Customer Interaction History.

Affected products

  • Oracle E-Business Suite Customer Interaction History 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats