Junglewise Threat Intelligence

CVE-2026-83450: Oracle Bills of Material privilege escalation in Setup Workbench

CVE-2026-83450 · Severity: high · CVSS 8 · Published 2026-09-15

Technologies: Oracle Bills of Material. Vendors: Oracle.

Executive brief

Oracle Bills of Material is a component of Oracle E-Business Suite used for managing product structures and manufacturing data. A vulnerability in the Setup Workbench component allows a highly privileged attacker with network access to compromise the system, potentially affecting confidentiality, integrity, and availability of data across related systems.

Technical details

This is a difficult-to-exploit vulnerability in Oracle Bills of Material (Oracle E-Business Suite component Setup Workbench) affecting versions 12.2.3–12.2.15. The vulnerability requires high privileges and network access via HTTP; no user interaction is required. Successful exploitation results in complete takeover of the Bills of Material system. The vulnerability exhibits scope change—attacks originate in Bills of Material but can significantly impact additional E-Business Suite products. A patch or update is expected from Oracle; check their September 2026 security advisory for remediation details.

Affected products

  • Oracle Bills of Material 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats