Impact
CVE-2026-83169 is a vulnerability in Oracle One‑to‑One Fulfillment, part of Oracle E‑Business Suite. The flaw resides in the Java Server component and allows an unauthenticated attacker to send crafted HTTP requests that can be leveraged for remote code execution. Successfully exploiting this defect results in compromise of the fulfillment application, with full control of data and processor execution – effectively taking over the entire instance.
Affected Systems
The vulnerability affects Oracle One‑to‑One Fulfillment with supported versions 12.2.3 through 12.2.15. It pertains exclusively to the Java Server handling HTTP traffic for this product; no other vendors or products are affected.
Risk and Exploitability
The CVSS base score of 8.1 classifies the issue as high severity, with confidentiality, integrity and availability all impacted. Attacker requirements are minimal – mere network connectivity to the HTTP interface, no user credentials, and no privileged access. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. However, its remote nature and the magnitude of potential damage warrant immediate remediation.
OpenCVE Enrichment