Description
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data as well as unauthorized update, insert or delete access to some of Oracle Field Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Field Service. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Partial Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in Oracle Field Service allows a low privileged attacker with network access via HTTP to gain unauthorized access to critical data. The flaw is an insecure direct object reference (CWE-284), enabling the attacker to read, update, insert, or delete data, and also to trigger a partial denial of service. The impact affects confidentiality (high), integrity (low), and availability (low), which together raise the overall threat level.

Affected Systems

The affected product is Oracle Corporation: Oracle Field Service, specifically the Internal Operations component. Versions 12.2.3 through 12.2.15 are impacted. The flaw is reachable over standard HTTP connections exposed to the network.

Risk and Exploitability

The CVSS 3.1 score of 7.6 indicates a high severity vulnerability. The EPSS score is less than 1%, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers would typically target the HTTP interface, require only low privileges, and no user interaction. If exploited, the attacker could compromise a breadth of data and partially disrupt service availability.

Generated by OpenCVE AI on September 20, 2026 at 11:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Field Service patch or upgrade to a version that is not listed as affected.
  • Restrict HTTP access to Oracle Field Service using network firewalls or VPNs so only trusted hosts can reach the application.
  • Enforce strict role‑based access controls within the application to limit the ability to read, modify, or delete data.
  • Monitor application logs for anomalous activity that may indicate attempts to exploit this flaw.

Generated by OpenCVE AI on September 20, 2026 at 11:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attack Yields Unauthorized Data Access in Oracle Field Service

Sun, 20 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Oracle Field Service: Unauthorized Access via HTTP for Low-Privileged Attackers
Weaknesses CWE-862

Thu, 17 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Title Oracle Field Service: Unauthorized Access via HTTP for Low-Privileged Attackers
Weaknesses CWE-862

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data as well as unauthorized update, insert or delete access to some of Oracle Field Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Field Service. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle field Service
CPEs cpe:2.3:a:oracle:field_service:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle field Service
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Field Service
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:58:19.417Z

Reserved: 2026-08-31T15:40:57.339Z

Link: CVE-2026-83091

cve-icon Vulnrichment

Updated: 2026-09-16T17:56:01.955Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:18.957

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:45:12Z

Weaknesses