Junglewise Threat Intelligence

CVE-2026-83433: Oracle Depot Repair unauthorized data access in E-Business Suite

CVE-2026-83433 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle Depot Repair is a component of Oracle E-Business Suite used for managing equipment repair and diagnostics. A network-accessible vulnerability allows privileged attackers to gain unauthorized access to create, modify, or delete critical business data. This could result in data loss, data theft, or operational disruption affecting repair records and equipment management.

Technical details

This is an authorization or access control vulnerability in the Depot Repair Diagnostics component of Oracle E-Business Suite. The vulnerability requires high privileges (authenticated administrator or similar role) and network access via HTTP to exploit, with no additional user interaction needed. A successful exploit allows an attacker with elevated credentials to read, modify, or delete sensitive data within the Oracle Depot Repair application. The CVSS 3.1 score of 6.5 reflects high confidentiality and integrity impacts with no availability impact. Patches are expected from Oracle's standard security update cycle.

Affected products

  • Oracle E-Business Suite 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats