Junglewise Threat Intelligence

CVE-2026-83174: Oracle E-Business Suite CRM Technical Foundation data access vulnerability

CVE-2026-83174 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle E-Business Suite CRM Technical Foundation. Vendors: Oracle.

Executive brief

Oracle E-Business Suite's CRM Technical Foundation component contains a vulnerability that allows a low-privileged attacker with network access to compromise critical customer relationship management data. Successful exploitation enables unauthorized viewing, modification, or deletion of sensitive CRM data, posing a significant risk to customer privacy and business operations.

Technical details

The vulnerability in the Application Framework component of Oracle CRM Technical Foundation is easily exploitable and requires only low privilege HTTP network access, with no user interaction required. The flaw enables attackers to gain unauthorized access to and modify critical CRM data stored within the affected system. Versions 12.2.3 through 12.2.15 are impacted. While detailed technical root cause information is limited, the attack vector is network-based over HTTP and affects the integrity and confidentiality of application data.

Affected products

  • Oracle E-Business Suite CRM Technical Foundation 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats