Junglewise Threat Intelligence

CVE-2026-83447: Oracle Bills of Material privilege escalation in E-Business Suite

CVE-2026-83447 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Bills of Material. Vendors: Oracle.

Executive brief

Oracle Bills of Material is a module within Oracle E-Business Suite used to manage product structures and component data in manufacturing operations. An easily exploitable vulnerability allows a low-privileged employee or contractor with network access to modify, delete, or create bill of materials records, potentially disrupting production planning, inventory management, and supply chain operations while also accessing confidential product design and cost data.

Technical details

The vulnerability is an authorization bypass or privilege escalation flaw in the Bills of Material component (Internal Operations) of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. The vulnerability is exploitable remotely via HTTP by an authenticated attacker with low privileges, requiring no user interaction. A successful exploit allows unauthorized creation, modification, and deletion of bill of materials records, as well as unauthorized access to all accessible data in the module. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) indicates a network-accessible flaw with low complexity and high impact on both confidentiality and integrity. Patch availability is not explicitly confirmed in the advisory text provided.

Affected products

  • Oracle Bills of Material 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats