Executive brief
Oracle Mobile Application Server (MWA Terminal Server) is a component of Oracle E-Business Suite used to enable mobile access to critical business applications. An unauthenticated attacker can remotely exploit this vulnerability over the network to gain complete control of the application server, potentially compromising all data and operations handled by the system.
Technical details
This is a network-exploitable vulnerability in the Oracle Mobile Application Server's MWA Terminal Server component that requires no authentication or user interaction. The vulnerability allows unauthenticated attackers with network access via TCP to achieve complete remote code execution or system compromise. Affected versions include Oracle E-Business Suite 12.2.3 through 12.2.15. The vulnerability results in full compromise of the affected application server including confidentiality, integrity, and availability impacts. Patches are expected as part of Oracle's security updates.
Affected products
- Oracle E-Business Suite Mobile Application Server (MWA Terminal Server) 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed: CVE-2026-83462 published