Junglewise Threat Intelligence

CVE-2026-83451: Oracle E-Business Suite Product Workbench privilege escalation

CVE-2026-83451 · Severity: high · CVSS 8.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Product Workbench is a component of Oracle E-Business Suite used for internal operations management. A vulnerability in this web-based product allows authenticated attackers to escalate privileges and gain full control over the application, with potential to impact other connected systems in the E-Business Suite environment.

Technical details

This is a privilege escalation vulnerability in the Oracle Product Workbench component of E-Business Suite affecting versions 12.2.3 through 12.2.15. The vulnerability requires low-privilege authentication and network access via HTTP, with a difficult exploit path (high complexity). Successful exploitation leads to complete compromise (confidentiality, integrity, and availability impact) with scope change, indicating that while the bug resides in Product Workbench, the impact extends to other E-Business Suite products. The vulnerability has not been publicly exploited as of the advisory date.

Affected products

  • Oracle E-Business Suite Product Workbench 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References