Junglewise Threat Intelligence

CVE-2026-83464: Oracle Mobile Application Server unauthenticated network compromise

CVE-2026-83464 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Mobile Application Server. Vendors: Oracle.

Executive brief

Oracle Mobile Application Server is a component of Oracle E-Business Suite that manages mobile application access and connectivity. An unauthenticated attacker with network access can exploit a difficult-to-exploit vulnerability to achieve complete takeover of the server, potentially compromising the entire E-Business Suite environment and all dependent mobile applications and business processes.

Technical details

The vulnerability exists in the MWA Terminal Server component of Oracle Mobile Application Server and allows unauthenticated attackers with network-level access via TCP to achieve remote code execution or equivalent compromise. While the vulnerability is classified as difficult to exploit (high attack complexity), successful exploitation results in complete compromise of the affected server (high confidentiality, integrity, and availability impact). Affected versions are 12.2.3 through 12.2.15. Patch availability and specific technical root cause details are not yet available in accessible security advisories.

Affected products

  • Oracle Mobile Application Server 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed
  • other: Not reported as exploited in the wild as of publication date

References

Related threats