Junglewise Threat Intelligence

CVE-2026-83445: Oracle E-Business Suite Complex Maintenance, Repair and Overhaul privilege escalation

CVE-2026-83445 · Severity: high · CVSS 8.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Complex Maintenance, Repair and Overhaul is a module within Oracle E-Business Suite used for managing maintenance and repair operations. A vulnerability in this component allows a low-privileged authenticated attacker to gain complete control over the system, potentially exposing or modifying critical maintenance records and operational data.

Technical details

The vulnerability is an easily exploitable privilege escalation flaw in Oracle E-Business Suite's Complex Maintenance, Repair and Overhaul component (Internal Operations). It requires low-level privileges and network access via HTTPS, but no additional user interaction. Successful exploitation allows an attacker to achieve complete system compromise, including unauthorized access to confidential information, modification of critical data, and denial of service. Affected versions include 12.2.3 through 12.2.15. Oracle has published security guidance; patch availability should be confirmed with Oracle advisories.

Affected products

  • Oracle E-Business Suite - Complex Maintenance, Repair and Overhaul 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats