Junglewise Threat Intelligence

CVE-2026-83171: Oracle One-to-One Fulfillment data access and denial of service vulnerability in Documents component

CVE-2026-83171 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle One-To-One Fulfillment. Vendors: Oracle.

Executive brief

A vulnerability in the Oracle One-to-One Fulfillment module (part of Oracle E-Business Suite) allows a low-privileged network attacker to access sensitive business data and disrupt service availability. One-to-One Fulfillment manages customer order fulfillment and document processing in enterprise resource planning systems. Successful exploitation could expose critical customer or operational data and cause partial service outages, impacting business operations across dependent applications.

Technical details

A difficult-to-exploit vulnerability exists in the Documents component of Oracle One-to-One Fulfillment, affecting versions 12.2.3 through 12.2.15. The vulnerability requires a low-privileged attacker with network access via HTTP to exploit, with no user interaction needed. Successful attacks can result in unauthorized read access to all data managed by the One-to-One Fulfillment module and partial denial of service; the vulnerability exhibits scope change, meaning the impact extends beyond the affected component to additional Oracle E-Business Suite products. The exploit complexity is high, mitigating ease of weaponization. Patch availability has not been confirmed in available advisory data.

Affected products

  • Oracle One-to-One Fulfillment 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats