Junglewise Threat Intelligence

CVE-2026-83179: Oracle E-Business Suite Common Applications Calendar privilege escalation

CVE-2026-83179 · Severity: high · CVSS 7.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle E-Business Suite's Common Applications Calendar is a scheduling and calendar management component used across enterprise environments. A privilege escalation vulnerability allows a low-privileged attacker with network access to modify, delete, or access critical calendar data, as well as disrupt the calendar service—potentially affecting business scheduling, resource planning, and operational continuity for organizations relying on this system.

Technical details

This is a privilege escalation and data manipulation vulnerability in the Common Applications Calendar component of Oracle E-Business Suite (versions 12.2.3–12.2.15) accessible via HTTP. The vulnerability requires low-level privileges and network access but does not require user interaction. An authenticated attacker can exploit this flaw to perform unauthorized creation, modification, or deletion of calendar data, access sensitive information, and cause partial denial of service. The difficulty of exploitation is high relative to the impact, suggesting the attack requires specific conditions or knowledge. No patch information is provided in the advisory.

Affected products

  • Oracle E-Business Suite Common Applications Calendar 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats