Junglewise Threat Intelligence

CVE-2026-83448: Oracle Bills of Material privilege escalation

CVE-2026-83448 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle E-Business Suite Bills of Material. Vendors: Oracle.

Executive brief

Oracle Bills of Material is a component of Oracle E-Business Suite used to manage manufacturing and production data. A vulnerability allows a low-privileged user with network access to gain unauthorized access to sensitive manufacturing data, including the ability to create, modify, or delete critical records. This could result in data breaches, unauthorized changes to bill-of-materials records, and operational disruption.

Technical details

The vulnerability is an easily exploitable flaw in Oracle Bills of Material (Oracle E-Business Suite component: Internal Operations) affecting versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit this to achieve unauthorized data access and modification. The attack requires low privilege level and network reachability but no user interaction. Successful exploitation results in confidentiality and integrity impacts including unauthorized creation, deletion, or modification of critical data. A patch or update is likely available from Oracle's security advisory.

Affected products

  • Oracle E-Business Suite Bills of Material 12.2.3 through 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats