Junglewise Threat Intelligence

CVE-2026-83167: Oracle Application Object Library unauthorized data access

CVE-2026-83167 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle E-Business Suite Application Object Library. Vendors: Oracle.

Executive brief

Oracle Application Object Library, a core component of Oracle E-Business Suite, contains a vulnerability that allows unauthenticated attackers to access sensitive business data over the network. Attackers can exploit this flaw without authentication to gain unauthorized access to critical financial, operational, and customer data stored within the application, potentially exposing confidential business information.

Technical details

This is an easily exploitable vulnerability in the Core component of Oracle Application Object Library affecting versions 12.2.3 through 12.2.15. The vulnerability can be triggered by an unauthenticated attacker with network access via HTTP, requiring no user interaction or special privileges. Successful exploitation results in unauthorized disclosure of sensitive data accessible through Oracle Application Object Library, with confidentiality being the primary impact. The CVSS 3.1 Base Score is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), indicating a network-based attack with low complexity and high confidentiality impact.

Affected products

  • Oracle E-Business Suite Application Object Library 12.2.3 through 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats