Junglewise Threat Intelligence

CVE-2026-83428: Oracle Demand Signal Repository data access vulnerability in E-Business Suite

CVE-2026-83428 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Demand Signal Repository. Vendors: Oracle.

Executive brief

Oracle Demand Signal Repository is a component within Oracle E-Business Suite that manages critical demand forecasting and inventory planning data for enterprises. A vulnerability allows low-privileged attackers with network access to read, modify, or delete sensitive business data without proper authorization, potentially exposing or corrupting supply chain and operational information essential to business continuity.

Technical details

The vulnerability exists in the Internal Operations component of Oracle Demand Signal Repository (versions 12.2.3 through 12.2.15) and is exploitable over the network via HTTP by low-privileged attackers without requiring user interaction. The flaw permits unauthorized data access and modification, compromising both confidentiality and integrity of stored data. The attack requires low privilege authentication but no complex exploitation techniques (CVSS AC:L). Affected organizations should apply security patches from Oracle's September 2026 Critical Patch Update when available.

Affected products

  • Oracle Demand Signal Repository 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats