Description
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in takeover of Oracle User Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in the Proxy User Delegation component of Oracle User Management. An attacker with only low privileges but who can reach the application over HTTP can exploit the flaw to gain full control of the User Management system. Successful exploitation enables the attacker to read, modify, or delete user data and disrupt availability, thereby breaching confidentiality, integrity, and availability.

Affected Systems

Oracle Corporation’s Oracle User Management product of Oracle E‑Business Suite is affected. The flaw is present in all versions from 12.2.3 through 12.2.15 inclusive.

Risk and Exploitability

The CVSS Base score of 8.8 indicates high severity. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at present, and the issue is not listed in CISA’s KEV catalog. The attack requires only network access over HTTP from a low privileged account, which makes the vulnerability readily exploitable in environments where Oracle User Management is exposed to untrusted networks. The CVSS vector confirms that the exploitation requires network access, low privilege, and no user interaction.

Generated by OpenCVE AI on September 20, 2026 at 09:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the security patch released by Oracle as described in the official advisory at https://www.oracle.com/security-alerts/cspusep2026.html
  • Restrict HTTP access to Oracle User Management to trusted internal networks or VPN only so that only authorized users can reach the service
  • Disable or remove the Proxy User Delegation feature if it is not required, to eliminate the attack surface

Generated by OpenCVE AI on September 20, 2026 at 09:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Proxy User Delegation in Oracle User Management

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Proxy User Delegation in Oracle User Management
Weaknesses CWE-284
CWE-287

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Proxy User Delegation in Oracle User Management
Weaknesses CWE-284
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in takeover of Oracle User Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle user Management
CPEs cpe:2.3:a:oracle:user_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle user Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle User Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:42.720Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83189

cve-icon Vulnrichment

Updated: 2026-09-17T13:01:55.304Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:30.280

Modified: 2026-09-17T14:17:35.363

Link: CVE-2026-83189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:15:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management