Junglewise Threat Intelligence

CVE-2026-83170: Oracle One-to-One Fulfillment privilege escalation in Documents component

CVE-2026-83170 · Severity: high · CVSS 8 · Published 2026-09-15

Technologies: Oracle E-Business Suite One-to-One Fulfillment. Vendors: Oracle.

Executive brief

A vulnerability in Oracle E-Business Suite's One-to-One Fulfillment product allows a low-privileged user with network access to the system to gain complete control of the application. Successful exploitation could enable an attacker to read sensitive customer and order data, modify fulfillment records, or disrupt order processing operations that customers rely on.

Technical details

A privilege escalation vulnerability exists in the Documents component of Oracle One-to-One Fulfillment (part of Oracle E-Business Suite) affecting versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable by a low-privileged attacker with access to the physical communication segment of the network where the application executes. No user interaction is required. Successful exploitation results in complete compromise of the application with high impact to confidentiality, integrity, and availability. Oracle has not yet published patched versions at the time of this advisory's release.

Affected products

  • Oracle E-Business Suite One-to-One Fulfillment 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats