Junglewise Threat Intelligence

CVE-2026-83338: Oracle E-Business Suite Applications Manager authentication bypass

CVE-2026-83338 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle E-Business Suite Applications Manager. Vendors: Oracle.

Executive brief

Oracle Applications Manager is a component of Oracle E-Business Suite used for system administration and diagnostics. A network-accessible vulnerability allows low-privileged users to bypass authentication controls and gain full control of the application, potentially exposing sensitive business data, enabling unauthorized changes to critical ERP configurations, and disrupting operations.

Technical details

This vulnerability exists in the Oracle Diagnostics Interfaces component of Oracle Applications Manager (versions 12.2.3 through 12.2.15). The flaw allows an attacker with low privileges and network access via HTTP to exploit an authentication or authorization weakness without requiring user interaction. Successful exploitation results in complete compromise of the Applications Manager, potentially allowing takeover of the system and access to sensitive enterprise data. The CVSS 3.1 vector indicates high impact across confidentiality, integrity, and availability. Patch availability should be verified through Oracle's official security updates.

Affected products

  • Oracle E-Business Suite Applications Manager 12.2.3 through 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats