Junglewise Threat Intelligence

CVE-2026-83444: Oracle E-Business Suite Product Hub privilege escalation

CVE-2026-83444 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle Product Hub, Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle Product Hub is a component of Oracle E-Business Suite used for managing product-related operations. A vulnerability allows low-privileged users with network access to gain full control of the application, compromising confidentiality, integrity, and availability of the system.

Technical details

This is a privilege escalation vulnerability in the Oracle Product Hub component of E-Business Suite. The vulnerability is easily exploitable and requires only low privilege authentication and network access via HTTP; no special user interaction is needed. A successful attack allows an attacker to fully compromise the Product Hub system, including unauthorized data access, modification, and service disruption. The vulnerability affects versions 12.2.3 through 12.2.15.

Affected products

  • Oracle E-Business Suite 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats