Junglewise Threat Intelligence

CVE-2026-83441: Oracle E-Business Suite Product Hub privilege escalation in Internal Operations

CVE-2026-83441 · Severity: medium · CVSS 6.8 · Published 2026-09-15

Technologies: Oracle Product Hub, Oracle E-Business Suite Product Hub. Vendors: Oracle.

Executive brief

Oracle Product Hub is a component of Oracle E-Business Suite that manages product information and related operations. An attacker with low-privilege network access can exploit this vulnerability to create, delete, or modify critical business data without authorization, as well as access sensitive information that should be restricted. This could lead to data integrity violations, unauthorized changes to product information, and exposure of confidential business data.

Technical details

The vulnerability in Oracle Product Hub's Internal Operations component is classified as a privilege escalation flaw affecting versions 12.2.3 through 12.2.15. It requires network access via HTTP and low-level privileges, with no user interaction needed. The attack is difficult to exploit due to high complexity requirements (AC:H). A successful attack grants an attacker unauthorized data manipulation (creation/deletion/modification) and full read access to sensitive Product Hub data. Patch availability and specific technical mitigations have not been confirmed from the available advisory sources.

Affected products

  • Oracle E-Business Suite Product Hub 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats