Description
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Full framework compromise
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an authentication bypass in the Oracle Applications Framework’s Personalization component. An attacker with network access can send specially crafted SOAP requests to the framework without providing any credentials, because the component fails to enforce proper authentication. Successful exploitation allows the attacker to execute arbitrary operations with the privileges of the framework, potentially leading to complete takeover of the application.

Affected Systems

Oracle Corporation’s Oracle Applications Framework, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. These include the Personalization service, and any deployment of the framework within the specified E‑Business Suite releases.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 base score of 9.8, reflecting critical confidentiality, integrity, and availability impacts. The EPSS score is below 1 %, indicating a currently low likelihood of exploitation, yet the severity warrants immediate action. The risk remains high because the attack vector is network‑based via unauthenticated SOAP calls, enabling full compromise of the framework without requiring prior access. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 18, 2026 at 14:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Applications Framework patch or update to a version beyond 12.2.15, as detailed in the Oracle Security Alert referenced in the advisory.
  • If a patch is not yet available, isolate the affected system from public networks and restrict SOAP traffic to trusted IP addresses or subnets using firewall or network segmentation rules.
  • Audit application logs for suspicious SOAP activity and confirm that authentication checks are currently enforced; if not, implement additional application‑level authentication controls or enable TLS for SOAP messages.

Generated by OpenCVE AI on September 18, 2026 at 14:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP-based Remote Compromise in Oracle Applications Framework

Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Framework
CPEs cpe:2.3:a:oracle:applications_framework:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Framework
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:35.242Z

Reserved: 2026-08-31T15:40:57.353Z

Link: CVE-2026-83327

cve-icon Vulnrichment

Updated: 2026-09-15T22:44:50.494Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:45.880

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:00:10Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function