Junglewise Threat Intelligence

CVE-2026-83465: Oracle Mobile Application Server denial of service and data manipulation

CVE-2026-83465 · Severity: high · CVSS 8.2 · Published 2026-09-15

Technologies: Oracle Mobile Application Server. Vendors: Oracle.

Executive brief

Oracle Mobile Application Server, a critical component of the E-Business Suite used to manage enterprise applications, is vulnerable to a denial-of-service attack that can crash the server and allow unauthorized modification of business data. An attacker with network access can exploit this vulnerability if a user interacts with a malicious request, potentially disrupting operations and compromising data integrity across multiple interconnected systems.

Technical details

This is an easily exploitable vulnerability in Oracle Mobile Application Server (MWA Terminal Server component) that requires network access via HTTP and user interaction. The vulnerability allows an unauthenticated attacker to cause a denial of service (server hang or crash) and gain unauthorized update/insert/delete access to application data. The vulnerability affects versions 12.2.3 through 12.2.15 and has scope change implications, meaning successful exploitation can impact systems beyond the directly vulnerable application. Patches are available from Oracle as indicated in the official security advisory.

Affected products

  • Oracle Mobile Application Server 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats