Junglewise Threat Intelligence

CVE-2026-83431: Oracle Product Workbench cross-site request forgery in WebUI

CVE-2026-83431 · Severity: medium · CVSS 5.4 · Published 2026-09-15

Technologies: Oracle Product Workbench. Vendors: Oracle.

Executive brief

Oracle Product Workbench is a component of Oracle E-Business Suite used for product configuration and management. This vulnerability allows a low-privileged attacker with network access to trick authorized users into unknowingly modifying or viewing sensitive product data through a malicious webpage, compromising the confidentiality and integrity of business-critical product information.

Technical details

This is a cross-site request forgery (CSRF) or similar UI-based vulnerability in the WebUI component of Oracle Product Workbench affecting versions 12.2.3 through 12.2.15. The vulnerability requires low-level privileges and network access via HTTP, but critically depends on user interaction (phishing or social engineering) to succeed. A successful attack results in unauthorized read, update, insert, or delete operations on accessible data within Product Workbench, and may have cascading impacts on other Oracle E-Business Suite products due to scope change. Patch availability has not been confirmed at the time of this advisory.

Affected products

  • Oracle Product Workbench 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats