Junglewise Threat Intelligence

CVE-2026-83172: Oracle Sales Online authentication bypass in E-Business Suite

CVE-2026-83172 · Severity: high · CVSS 8.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Sales Online is a component of Oracle E-Business Suite used for managing sales operations and customer data. This vulnerability allows an authenticated user with network access to bypass security controls and gain unauthorized access to sensitive sales data, including the ability to read, modify, or delete records across the system. The flaw could expose critical customer and financial information or lead to data integrity issues.

Technical details

This is an easily exploitable network-accessible vulnerability in Oracle Sales Online (component: OSO Other) affecting versions 12.2.3 through 12.2.15. The vulnerability requires low privilege authentication and HTTP access; no user interaction is needed. An attacker can achieve unauthorized access to critical data and modify or delete certain accessible records. The scope is marked as "changed," indicating attacks on Oracle Sales Online may impact other Oracle E-Business Suite products. Patches are expected from Oracle's security updates.

Affected products

  • Oracle Sales Online 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats