Junglewise Threat Intelligence

CVE-2026-83205: Oracle E-Business Suite Applications Framework privilege escalation in Personalization

CVE-2026-83205 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite's Applications Framework is a core component that enables personalization and customization of business applications used by enterprises to manage financial, HR, and supply chain operations. A flaw in the Personalization component allows a low-privilege user with network access to gain complete control of the framework, potentially compromising sensitive business data, transaction integrity, and system availability across the entire suite.

Technical details

This is a privilege escalation vulnerability in the Oracle Applications Framework's Personalization component affecting versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable and requires only low-privilege user credentials and network access via HTTP; no user interaction is needed. A successful attack grants an attacker complete compromise of the framework with impacts to confidentiality, integrity, and availability. The advisory does not provide specific technical details about the root cause or patch status, but the CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms network accessibility, low attack complexity, and low privilege requirements.

Affected products

  • Oracle E-Business Suite 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats