Junglewise Threat Intelligence

CVE-2026-83300: Oracle XML Gateway Install component unauthorized access and DoS in E-Business Suite

CVE-2026-83300 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Xml Gateway. Vendors: Oracle.

Executive brief

Oracle XML Gateway is a critical middleware component within Oracle E-Business Suite used for enterprise data integration and messaging. A low-privileged attacker with network access can exploit this vulnerability to read sensitive business data and disrupt service availability, potentially affecting order processing, supply chain operations, and financial integrations.

Technical details

This is an easily exploitable vulnerability in the Oracle XML Gateway Install component affecting versions 12.2.3–12.2.15. The vulnerability allows a low-privileged, network-accessible attacker (via HTTP) to bypass authorization controls and access restricted data or cause partial denial of service. The attack requires valid authentication (PR:L) but no user interaction. Successful exploitation results in high confidentiality impact (unauthorized access to critical and all accessible data) and low availability impact (partial DoS). A patch is available via Oracle's September 2026 Critical Patch Update.

Affected products

  • Oracle XML Gateway 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats