Junglewise Threat Intelligence

CVE-2026-83173: Oracle E-Business Suite One-to-One Fulfillment authentication bypass in Documents

CVE-2026-83173 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle E-Business Suite One-to-One Fulfillment. Vendors: Oracle.

Executive brief

Oracle E-Business Suite's One-to-One Fulfillment module is used to manage customer orders and document workflows in enterprise procurement systems. A vulnerability allows an authenticated user with network access to bypass authorization controls and access sensitive order and customer data, or cause partial service disruption. This could expose confidential business information and disrupt order fulfillment operations.

Technical details

A logic flaw in the Documents component of Oracle One-to-One Fulfillment allows a low-privileged, authenticated user to escalate access and retrieve critical data beyond their authorization scope. The vulnerability is network-reachable via HTTP and requires valid user credentials but no additional user interaction. An attacker can read sensitive data across the fulfillment system and potentially degrade availability of the service. Oracle has assigned CVSS 3.1 score 7.1 (High) reflecting the combination of high confidentiality impact and partial availability impact. Patches are expected from Oracle's September 2026 security update cycle.

Affected products

  • Oracle E-Business Suite One-to-One Fulfillment 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory: Oracle CPU September 2026

References

Related threats