Junglewise Threat Intelligence

CVE-2026-83484: Oracle E-Business Suite US Federal Human Resources unauthorized data access

CVE-2026-83484 · Severity: high · CVSS 7.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle E-Business Suite includes a US Federal Human Resources module used by government agencies to manage employee records and personnel data. A vulnerability allows a low-privileged authenticated attacker on the network to read sensitive employee information and modify or delete critical personnel records without proper authorization, creating compliance and operational risks.

Technical details

The vulnerability in the Internal Operations component of Oracle US Federal Human Resources permits unauthorized data access via the HTTP interface to users with low privilege credentials. It requires network connectivity and valid authentication to exploit, but does not require user interaction. Successful exploitation enables unauthorized read access to a subset of sensitive data and broad create, delete, and modification permissions on critical records. The vulnerability affects versions 12.2.3 through 12.2.15; patches are expected from Oracle's regular security update cycle.

Affected products

  • Oracle E-Business Suite US Federal Human Resources 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats