Description
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Critical Data
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from improper access control and authentication in the Audience component of Oracle Marketing. An unauthenticated attacker who can reach the application over HTTP can retrieve sensitive marketing data without providing credentials, leading to disclosure of confidential customer information. The flaw is classified as an authentication bypass and a lack of adequate access control (CWE-284).

Affected Systems

Oracle Marketing, part of Oracle E-Business Suite, versions 12.2.3 through 12.2.15, is affected. The issue exists in the Audience component that exposes customer and campaign data.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high‑severity vulnerability that impacts confidentiality. The EPSS score is in the (0%,1%) interval, indicating a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Nevertheless, because the vulnerability can be triggered simply by sending HTTP requests without authentication, it can be exploited remotely by any adversary with network access to the Marketing web services.

Generated by OpenCVE AI on September 20, 2026 at 09:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses CVE-2026-83110 for Oracle Marketing versions 12.2.3‑12.2.15.
  • Limit external access to the Oracle Marketing web services by restricting traffic to trusted networks or requiring VPN.
  • Configure the Audience component to require authentication or disable insecure HTTP methods to prevent unauthenticated data access.

Generated by OpenCVE AI on September 20, 2026 at 09:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Marketing Data in Oracle E-Business Suite

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leading to Data Disclosure in Oracle Marketing
Weaknesses CWE-287

Thu, 17 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leading to Data Disclosure in Oracle Marketing
Weaknesses CWE-287

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle marketing
CPEs cpe:2.3:a:oracle:marketing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle marketing
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Marketing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:57:55.703Z

Reserved: 2026-08-31T15:40:57.340Z

Link: CVE-2026-83110

cve-icon Vulnrichment

Updated: 2026-09-16T17:52:16.951Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:21.223

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83110

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:45:17Z

Weaknesses