Junglewise Threat Intelligence

CVE-2026-83187: Oracle E-Business Suite Common Applications Calendar data manipulation

CVE-2026-83187 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite includes a Calendar application used by organizations to manage schedules and events across the enterprise. A vulnerability allows low-privileged network users to create, delete, or modify calendar data and read sensitive information without proper authorization. An attacker with basic system access could corrupt critical business schedules, access confidential meeting details, or plant malicious events.

Technical details

This is an authorization/access control flaw in the Oracle Common Applications Calendar component of E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable via HTTP by a low-privileged, authenticated attacker without user interaction required. An attacker can bypass access controls to create, modify, or delete calendar entries, as well as read a subset of calendar data they should not have access to. The attack requires network access and valid credentials but no elevated privileges. No patch information is currently available in the provided advisory.

Affected products

  • Oracle E-Business Suite 12.2.3 through 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats