Description
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in takeover of Oracle User Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows an attacker with low privileges and network access over HTTP to fully compromise the Oracle User Management component of Oracle E‑Business Suite. Once exploited, the attacker can gain control of the application, undermining the confidentiality, integrity, and availability of the system.

Affected Systems

It affects Oracle User Management in the Oracle E‑Business Suite, with supported affected versions ranging from 12.2.6 through 12.2.15.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 reflects a high severity, and an EPSS score of less than 1% indicates a very low yet nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a network attack via HTTP, requiring only low privilege credentials or access rights to succeed.

Generated by OpenCVE AI on September 20, 2026 at 10:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for User Management, updating to at least version 12.2.15 or newer.
  • Restrict HTTP access to the User Management service by configuring firewall rules to allow traffic only from trusted network segments or VPN endpoints.
  • Enforce strict role separation by eliminating unnecessary administrative accounts and monitor authentication logs for anomalous activity.

Generated by OpenCVE AI on September 20, 2026 at 10:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploitation of Oracle User Management in Oracle E‑Business Suite

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Exploit in Oracle User Management Leading to Full Takeover
Weaknesses CWE-284
CWE-287

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Exploit in Oracle User Management Leading to Full Takeover
Weaknesses CWE-284
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in takeover of Oracle User Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle user Management
CPEs cpe:2.3:a:oracle:user_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle user Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle User Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:44.069Z

Reserved: 2026-08-31T15:40:57.341Z

Link: CVE-2026-83119

cve-icon Vulnrichment

Updated: 2026-09-17T13:02:22.473Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:22.260

Modified: 2026-09-17T14:17:34.007

Link: CVE-2026-83119

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:15:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management