Junglewise Threat Intelligence

CVE-2026-83440: Oracle E-Business Suite Product Hub privilege escalation

CVE-2026-83440 · Severity: high · CVSS 7.2 · Published 2026-09-15

Technologies: Oracle Product Hub, Oracle E-Business Suite Product Hub. Vendors: Oracle.

Executive brief

Oracle Product Hub is a core component of Oracle E-Business Suite used to manage product data and operations. A privilege escalation vulnerability allows high-privileged attackers to gain complete control of the Product Hub system via network access, compromising data confidentiality, integrity, and system availability.

Technical details

This vulnerability in Oracle E-Business Suite's Product Hub (Internal Operations component) is exploitable by high-privileged attackers with network access over HTTP. The vulnerability requires high privileges and allows network-based exploitation without user interaction. Successful exploitation results in full compromise of the Product Hub system, affecting confidentiality, integrity, and availability. Affected versions are 12.2.3 through 12.2.15; patches are available from Oracle's security alerts.

Affected products

  • Oracle E-Business Suite Product Hub 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed
  • other: CVE-2026-83440 assigned

References

Related threats