Description
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Field Service accessible data as well as unauthorized access to critical data or complete access to all Oracle Field Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Field Service. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification, deletion, or creation of data and potential partial denial of service within Oracle Field Service
Action: Immediate Patch
AI Analysis

Impact

Oracle Field Service allows a low‑privileged network attacker to perform unauthorized data operations—creation, deletion, or modification—via HTTP requests, as well as potentially cause a partial denial of service. This flaw arises from missing or improper access controls (CWE‑284) and unchecked permissions before sensitive actions, leading to large confidentiality and integrity impacts (CVSS 3.1 Base Score 7.1). The flaw resides in the Internal Operations component of Oracle E‑Business Suite and permits these actions without requiring user authentication, but does require network access to the HTTP interface. The available description does not explicitly state that authentication is required; it is inferred that an attacker does not need prior authentication to exploit this vulnerability.

Affected Systems

Oracle Field Service versions 12.2.3 through 12.2.15 are affected. The flaw exists within the Internal Operations component of Oracle E‑Business Suite. No other versions or components are listed as impacted.

Risk and Exploitability

The EPSS score is < 1 % and the issue is not listed in CISA KEV, yet the vulnerability remains high risk due to its confidentiality, integrity, and partial availability impacts; the CVSS base score is 7.1. An attacker only needs low privileges and direct network access to HTTP endpoints to exploit the flaw. The description does not explicitly state that authentication is required; it is inferred that no authentication or privileged escalation steps are needed.

Generated by OpenCVE AI on September 20, 2026 at 12:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle Field Service patch that removes the unauthorized access flaw (addressing CWE‑284) or upgrade to a supported version later than 12.2.15
  • If a patch is not immediately available, enforce strict access control by restricting external access to the Internal Operations HTTP endpoints through firewalls or network segmentation so only trusted internal systems can reach the service
  • Disable the Internal Operations component or remove unused REST interfaces to reduce the attack surface until a fully inclusive security fix is installed

Generated by OpenCVE AI on September 20, 2026 at 12:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Inadequate Access Control in Oracle Field Service

Sun, 20 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial Denial of Service via Low‑Privilege HTTP Exploit in Oracle Field Service
Weaknesses CWE-862

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial Denial of Service via Low‑Privilege HTTP Exploit in Oracle Field Service
Weaknesses CWE-284
CWE-862

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Field Service accessible data as well as unauthorized access to critical data or complete access to all Oracle Field Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Field Service. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).
First Time appeared Oracle
Oracle field Service
CPEs cpe:2.3:a:oracle:field_service:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle field Service
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Oracle Field Service
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:20:12.952Z

Reserved: 2026-08-31T15:40:57.339Z

Link: CVE-2026-83092

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:59.376Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:19.090

Modified: 2026-09-17T16:18:00.900

Link: CVE-2026-83092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:00:11Z

Weaknesses