Junglewise Threat Intelligence

CVE-2026-83345: Oracle XML Gateway HTTP authentication bypass in E-Business Suite

CVE-2026-83345 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle Xml Gateway. Vendors: Oracle.

Executive brief

Oracle XML Gateway is a component of Oracle E-Business Suite that handles XML-based data integration and electronic commerce transactions. A flaw allows an attacker with low-level credentials and network access to bypass authentication controls, potentially exposing sensitive business data and disrupting critical integration processes that depend on XML Gateway for order processing, invoicing, and inter-system communication.

Technical details

This vulnerability is an authentication bypass or authorization flaw in the Oracle XML Gateway install component (versions 12.2.3–12.2.15) that allows a low-privileged attacker with network access via HTTP to gain unauthorized access to sensitive data and trigger a partial denial of service. The attack requires valid credentials (low privilege level) but no user interaction, indicating the flaw exists in the authentication or access control logic of the gateway. An attacker can read critical data accessible through XML Gateway and degrade service availability. Patches should be available from Oracle's Critical Patch Update program.

Affected products

  • Oracle XML Gateway 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats