Description
Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering. While the vulnerability is in Oracle Engineering, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Engineering accessible data as well as unauthorized access to critical data or complete access to all Oracle Engineering accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Compromise (Integrity & Confidentiality)
Action: Immediate Patch
AI Analysis

Impact

This vulnerability permits a low‑privileged attacker who can reach the Oracle Engineering component over HTTP to create, delete, or modify critical data without proper authorization. The flaw results in unauthorized access to all data managed by Oracle Engineering, causing both confidentiality and integrity violations. The CVSS 3.1 base score of 8.2 underlines the severity with a high impact on confidentiality and integrity while the availability is not affected.

Affected Systems

Oracle Engineering, part of Oracle E‑Business Suite, is affected for supported releases from 12.2.3 through 12.2.15. The issue resides in the Internal Operations module. Attackers may also impact other components of Oracle E‑Business Suite due to a scope change. System administrators should verify that the version in use falls within this range.

Risk and Exploitability

The vulnerability can be exploited over the network using HTTP (AV:N) with high attack complexity (AC:H) and low privileges (PR:L) and no user interaction (UI:N). The EPSS score of less than 1% indicates a very low probability of widespread exploitation at this time, and it is not listed in the CISA KEV catalog. Nevertheless, the high CVSS score (8.2) and the potential for scope escalation warrant immediate attention from security teams.

Generated by OpenCVE AI on September 18, 2026 at 15:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest security patch for Oracle Engineering in the specified version range.
  • Configure network restrictions to limit HTTP access to the Oracle Engineering component to trusted sources only.
  • Review and enforce least privilege and proper authorization configurations for the Internal Operations component, ensuring that users cannot create, delete, or modify data without appropriate rights.
  • Monitor system logs for suspicious activity related to unauthorized data access or modifications.

Generated by OpenCVE AI on September 18, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Oracle Engineering Internal Operations data modification vulnerability
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering. While the vulnerability is in Oracle Engineering, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Engineering accessible data as well as unauthorized access to critical data or complete access to all Oracle Engineering accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle engineering
CPEs cpe:2.3:a:oracle:engineering:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle engineering
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Engineering
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:47.213Z

Reserved: 2026-08-31T15:40:57.359Z

Link: CVE-2026-83438

cve-icon Vulnrichment

Updated: 2026-09-18T18:15:23.595Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:52.410

Modified: 2026-09-18T19:17:01.187

Link: CVE-2026-83438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T16:00:09Z

Weaknesses