Junglewise Threat Intelligence

CVE-2026-83186: Oracle E-Business Suite Common Applications Calendar data modification vulnerability

CVE-2026-83186 · Severity: high · CVSS 7.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle E-Business Suite's Common Applications Calendar is a scheduling and calendar management component used across enterprise organizations. A vulnerability in versions 12.2.3 through 12.2.15 allows low-privileged network users to create, delete, or modify critical business data and cause service disruptions, directly impacting operational continuity and data integrity.

Technical details

This vulnerability is an integrity and availability issue in the Oracle Common Applications Calendar component of E-Business Suite. It is easily exploitable by a low-privileged attacker with network access via HTTP, requiring no user interaction. The flaw enables unauthorized modification or deletion of calendar data accessible through the affected product, as well as a partial denial-of-service condition. Versions 12.2.3 through 12.2.15 are affected. Oracle released a patch with the September 2026 Critical Patch Update.

Affected products

  • Oracle E-Business Suite Common Applications Calendar 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats