Junglewise Threat Intelligence

CVE-2026-83486: Oracle E-Business Suite Product Hub information disclosure in Item Catalog

CVE-2026-83486 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle Product Hub, Oracle E-Business Suite. Vendors: Oracle.

Executive brief

The Oracle Product Hub component within E-Business Suite, which manages product catalogs and item data, contains a vulnerability that allows attackers with low-level network access to view sensitive product data. An attacker could gain unauthorized access to critical business information stored in the product catalog without requiring privileged credentials, potentially exposing competitive or operational data across multiple connected Oracle systems.

Technical details

This is an information disclosure vulnerability in the Oracle Product Hub Item Catalog component. The vulnerability is easily exploitable via the network using HTTP by an attacker with low privileges (authenticated user), and requires no user interaction. The scope change indicates that while the flaw exists in Product Hub, successful exploitation can impact other Oracle E-Business Suite products. An attacker can achieve unauthorized access to critical data and potentially view all data accessible through Oracle Product Hub. The vulnerability affects versions 12.2.3 through 12.2.15 of E-Business Suite.

Affected products

  • Oracle E-Business Suite 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats