Junglewise Threat Intelligence

CVE-2026-83462: Oracle Mobile Application Server unauthenticated remote takeover

CVE-2026-83462 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Mobile Application Server (MWA Terminal Server) is a component of Oracle E-Business Suite used to enable mobile access to critical business applications. An unauthenticated attacker can remotely exploit this vulnerability over the network to gain complete control of the application server, potentially compromising all data and operations handled by the system.

Technical details

This is a network-exploitable vulnerability in the Oracle Mobile Application Server's MWA Terminal Server component that requires no authentication or user interaction. The vulnerability allows unauthenticated attackers with network access via TCP to achieve complete remote code execution or system compromise. Affected versions include Oracle E-Business Suite 12.2.3 through 12.2.15. The vulnerability results in full compromise of the affected application server including confidentiality, integrity, and availability impacts. Patches are expected as part of Oracle's security updates.

Affected products

  • Oracle E-Business Suite Mobile Application Server (MWA Terminal Server) 12.2.3 through 12.2.15

Timeline

  • 2026-09-15: disclosed: CVE-2026-83462 published

References