Junglewise Threat Intelligence

CVE-2026-83425: Oracle E-Business Suite Complex Maintenance Repair and Overhaul unauthorized access in Internal Operations

CVE-2026-83425 · Severity: high · CVSS 8.5 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite includes a Complex Maintenance, Repair and Overhaul product used by organizations to manage maintenance operations. A vulnerability in this product's Internal Operations component allows a low-privileged network user to gain unauthorized access to critical business data and partially disrupt service availability. The vulnerability could also impact other Oracle E-Business Suite components depending on system architecture.

Technical details

This vulnerability is an authorization or data access flaw in the Oracle Complex Maintenance, Repair and Overhaul product's Internal Operations component. The vulnerability is easily exploitable and requires only low-level privileges and network (HTTP) access to attack—no user interaction or complex configuration is needed. Successful exploitation allows an attacker to read sensitive data and trigger a partial denial of service. The scope is marked as changed, indicating that while the flaw resides in this product, the impact can cascade to other Oracle E-Business Suite modules. Patches are available; affected versions are 12.2.12 through 12.2.15.

Affected products

  • Oracle E-Business Suite 12.2.12–12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats