Junglewise Threat Intelligence

CVE-2026-83329: Oracle E-Business Suite Applications Framework privilege escalation in Personalization

CVE-2026-83329 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite is a widely used enterprise resource planning platform that manages core business operations for large organizations. A vulnerability in the Personalization component of the Applications Framework allows authenticated users to escalate privileges and completely compromise the system, exposing sensitive business data and potentially disrupting critical business processes.

Technical details

This is a privilege escalation vulnerability in the Oracle Applications Framework Personalization component, affecting versions 12.2.9 through 12.2.15. The vulnerability is easily exploitable and requires only low-privilege network access via HTTP with a valid user account (low privilege attacker); no additional user interaction is needed. Successful exploitation allows an attacker to achieve complete takeover of the Oracle Applications Framework, resulting in high impact to confidentiality, integrity, and availability. The vulnerability is remotely exploitable over the network, making it a significant risk for internet-facing or intranet deployments.

Affected products

  • Oracle E-Business Suite 12.2.9-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats