Junglewise Threat Intelligence

CVE-2026-83185: Oracle E-Business Suite Common Applications privilege escalation in CRM User Management Framework

CVE-2026-83185 · Severity: high · CVSS 7.3 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle E-Business Suite Common Applications contains a vulnerability in its CRM User Management Framework that allows a low-privileged user to manipulate critical business data when a victim clicks a malicious link. An attacker can create, delete, or modify sensitive customer relationship management data, potentially affecting business continuity and customer trust. Exploitation requires network access and user interaction, but the impact to data integrity and confidentiality is significant.

Technical details

This vulnerability in Oracle E-Business Suite's CRM User Management Framework allows a low-privileged attacker with network access to bypass authorization controls through an HTTP-based attack vector that requires user interaction (likely a clickjacking or CSRF attack). The vulnerability affects Common Applications versions 12.2.3 through 12.2.15. Successful exploitation results in unauthorized access to critical CRM data, with the ability to read, create, modify, or delete data within the affected component. The attack requires the victim to interact with attacker-controlled content (clicking a link or visiting a malicious page), making it a user-assisted privilege escalation vector with high impact on both confidentiality and integrity but no availability impact.

Affected products

  • Oracle E-Business Suite Common Applications 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References