Description
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in takeover of Oracle Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote System Compromise
Action: Immediate Patch
AI Analysis

Impact

An easily exploitable flaw exists in the Audience component of Oracle Marketing that allows a remote attacker with only network access via HTTP to achieve full takeover. The vulnerability can be leveraged by a low‑privileged user and results in catastrophic loss of confidentiality, integrity, and availability, with a CVSS 3.1 Base Score of 8.8.

Affected Systems

Oracle Marketing, part of Oracle E‑Business Suite, Audience component versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The high CVSS score indicates severe potential impact, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and the issue has not yet been recorded in the CISA KEV catalog. The attack vector is remote via HTTP, requiring only low privilege to execute, which can lead to complete application compromise if successful.

Generated by OpenCVE AI on September 20, 2026 at 09:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Marketing update or resolve the issue as detailed in the Oracle security alert linked above.
  • Restrict and monitor HTTP access to the Oracle Marketing application using firewall rules or network segmentation to limit exposure to trusted internal networks.
  • Implement intensive logging and anomaly detection on the Oracle Marketing application to identify and respond to suspicious activity early.

Generated by OpenCVE AI on September 20, 2026 at 09:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploitation of Oracle Marketing Audience Component Leads to Full Takeover

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover in Oracle Marketing Audience Component
Weaknesses CWE-284
CWE-295

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover in Oracle Marketing Audience Component
Weaknesses CWE-284
CWE-295

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in takeover of Oracle Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle marketing
CPEs cpe:2.3:a:oracle:marketing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle marketing
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Marketing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:43.770Z

Reserved: 2026-08-31T15:40:57.341Z

Link: CVE-2026-83121

cve-icon Vulnrichment

Updated: 2026-09-17T13:02:16.578Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:22.490

Modified: 2026-09-17T14:17:34.260

Link: CVE-2026-83121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:45:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management