Junglewise Threat Intelligence

CVE-2026-83434: Oracle Product Workbench unauthorized data access in E-Business Suite

CVE-2026-83434 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Product Workbench. Vendors: Oracle.

Executive brief

Oracle Product Workbench is a component of Oracle E-Business Suite used for product data management and operations. A vulnerability allows low-privileged users with network access to create, delete, or modify critical product data or read sensitive business information. This could enable unauthorized access to confidential product records, pricing, configurations, or operational data.

Technical details

The vulnerability in Oracle Product Workbench's Internal Operations component is easily exploitable and allows low-privileged attackers with network access via HTTP to bypass authorization controls. The flaw results in both confidentiality and integrity compromises, permitting unauthorized creation, deletion, modification, and reading of critical data accessible to the application. The vulnerability affects E-Business Suite versions 12.2.3 through 12.2.15. Patches are expected from Oracle's security advisory publication.

Affected products

  • Oracle Product Workbench 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed: Published in Oracle Critical Patch Update (September 2026)

References

Related threats