Description
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Application Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Technical Foundation accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification
Action: Patch Immediately
AI Analysis

Impact

A flaw in Oracle CRM Technical Foundation enables a low‑privileged attacker who can reach the product’s HTTP interface to create, delete or modify critical data. The weakness is a missing or insufficient access control that permits users to carry out privileged operations. This flaw compromises the confidentiality and integrity of all data accessible through the CRM.

Affected Systems

Oracle Corporation’s Oracle CRM Technical Foundation, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15. The vulnerability resides in the Application Framework component that processes HTTP requests for data manipulation.

Risk and Exploitability

The CVSS v3.1 Base Score of 8.1 indicates a high severity rating. The attack vector is network (AV:N) with low privileges (PR:L). The EPSS score of <1% suggests a low likelihood of exploitation in the wild at this time. The flaw is not listed in the CISA KEV catalog. An attacker with network access to the CRM’s HTTP interface can exploit the flaw to alter or delete data, jeopardizing business operations.

Generated by OpenCVE AI on September 20, 2026 at 09:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch for Oracle CRM Technical Foundation 12.2.3 through 12.2.15 to remediate the access control flaw.
  • Restrict HTTP or network ACLs to allow only trusted hosts to reach the vulnerable endpoints.
  • Review and enforce stricter access control policies within the CRM to ensure that only authorized users can create, delete, or modify critical data.

Generated by OpenCVE AI on September 20, 2026 at 09:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Data Modification via HTTP in Oracle CRM Technical Foundation

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Vulnerability Enabling Unauthorized Data Manipulation in Oracle CRM Technical Foundation
Weaknesses CWE-732

Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Vulnerability Enabling Unauthorized Data Manipulation in Oracle CRM Technical Foundation
Weaknesses CWE-284
CWE-732

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Application Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Technical Foundation accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle crm Technical Foundation
CPEs cpe:2.3:a:oracle:crm_technical_foundation:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle crm Technical Foundation
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Crm Technical Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:50.692Z

Reserved: 2026-08-31T15:40:57.344Z

Link: CVE-2026-83174

cve-icon Vulnrichment

Updated: 2026-09-18T18:16:46.471Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:28.440

Modified: 2026-09-18T19:16:49.400

Link: CVE-2026-83174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:45:17Z

Weaknesses