Junglewise Threat Intelligence

CVE-2026-83176: Oracle E-Business Suite Common Applications privilege escalation in CRM User Management

CVE-2026-83176 · Severity: high · CVSS 7.2 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

A high-privileged user in Oracle E-Business Suite can exploit a vulnerability in the CRM User Management Framework component to gain complete control over the Common Applications system. Successful exploitation could allow an attacker with administrative access to compromise confidentiality, integrity, and availability of critical business applications that manage customer relationships and core enterprise functions.

Technical details

This vulnerability in the Oracle E-Business Suite Common Applications component (CRM User Management Framework) allows a high-privileged attacker with network access via HTTP to achieve complete system compromise. The vulnerability is easily exploitable and requires high privilege level but no user interaction (UI:N). The attack vector is network-based (AV:N) with low attack complexity (AC:L), meaning an attacker with admin or privileged account credentials can directly trigger the flaw. Successful exploitation results in full compromise of confidentiality, integrity, and availability of the affected application. Affected versions range from 12.2.3 through 12.2.15; patch status should be verified with Oracle's security advisories.

Affected products

  • Oracle E-Business Suite 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory

References

Related threats