Junglewise Threat Intelligence

CVE-2026-83485: Oracle E-Business Suite Product Hub unauthorized data access

CVE-2026-83485 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle Product Hub, Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite's Product Hub is a module that manages product and item catalog data critical to order processing and inventory management. A vulnerability allows a low-privileged user with network access to read sensitive product data without authorization, potentially exposing pricing, inventory, and supplier information across the entire catalog. The impact extends beyond Product Hub to other connected systems that rely on this data.

Technical details

This is an authorization bypass vulnerability in the Oracle Product Hub Item Catalog component affecting versions 12.2.3–12.2.15. The flaw is easily exploitable over HTTP by an authenticated low-privilege user (no admin rights required), with no complex preconditions. The vulnerability results in a scope change—meaning an attacker can access resources outside the Product Hub module itself. Successful exploitation allows unauthorized reading of critical data, though modification and availability are not impacted. Oracle released a patch in the September 2026 Critical Patch Update.

Affected products

  • Oracle E-Business Suite 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched

References

Related threats