Junglewise Threat Intelligence

CVE-2026-83184: Oracle Application Object Library unauthenticated network access vulnerability

CVE-2026-83184 · Severity: high · CVSS 7.4 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle Application Object Library, a core component of Oracle E-Business Suite used for enterprise application management, contains a vulnerability allowing unauthenticated attackers to access the system over the network. An attacker could modify, delete, or view sensitive business data stored within the system, impacting data integrity and confidentiality.

Technical details

This is a difficult-to-exploit vulnerability in the Oracle Application Object Library component (Core) affecting E-Business Suite versions 12.2.3 through 12.2.15. It allows unauthenticated attackers with network access via HTTP to bypass authentication controls and gain unauthorized access to data. The vulnerability enables attackers to perform unauthorized creation, deletion, or modification of critical data, as well as read access to sensitive information. A patch is expected to be available from Oracle; consult Oracle's security advisory for specific patch timing and version information.

Affected products

  • Oracle E-Business Suite 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats