Junglewise Threat Intelligence

CVE-2026-83455: Oracle Demand Signal Repository unauthorized data access in E-Business Suite

CVE-2026-83455 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle E-Business Suite Demand Signal Repository. Vendors: Oracle.

Executive brief

Oracle Demand Signal Repository is a supply chain planning component within Oracle E-Business Suite that manages demand forecasting and inventory data. A low-privileged network attacker can exploit an easily exploitable vulnerability in versions 12.2.3-12.2.15 to read, modify, or delete critical business data, potentially compromising supply chain visibility and decision-making.

Technical details

The vulnerability in Oracle Demand Signal Repository (component: Internal Operations) is easily exploitable by a low-privileged attacker over the network via HTTP, requiring only valid user credentials (PR:L) and no user interaction. The vulnerability allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all accessible repository data. The root cause and specific vulnerable component are not detailed in available public references. Affected versions are 12.2.3 through 12.2.15 of Oracle E-Business Suite. Oracle has released fixes as part of their security updates; patched versions should be applied immediately.

Affected products

  • Oracle E-Business Suite Demand Signal Repository 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats