Description
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Total System Compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a privilege escalation flaw that can be triggered over an HTTP interface. A remote attacker who possesses high‑level authentication credentials can exploit the flaw to elevate privileges within the Oracle Document Management and Collaboration component. The flaw allows the adversary to gain full control of the application, thereby exposing confidential data, allowing modification of content, and disrupting availability. The weakness is identified as CWE‑269 (Improper Privilege Management), which directly relates to the attacker’s ability to bypass access controls.

Affected Systems

Oracle Document Management and Collaboration in Oracle E‑Business Suite, version range 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity, while the EPSS score of less than 1% suggests a very low likelihood that this vulnerability is being actively exploited. The vulnerability is not listed in the CISA KEV catalog, so there are no known widespread exploitation incidents. Exploitation requires HTTP access to the vulnerable endpoint and high‑privileged credentials; once those preconditions are met, the attacker can proceed with the privilege escalation without additional steps.

Generated by OpenCVE AI on September 20, 2026 at 06:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that fixes this issue, such as upgrading to version 12.2.15.2 or a later release.
  • Restrict HTTP access to the Document Management and Collaboration component to trusted IP ranges and enforce strict authentication policies to limit exposure of the vulnerable endpoint.
  • Monitor HTTP traffic for unusual requests targeting the affected endpoints and establish an incident response plan for suspected exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 06:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title High Privilege Escalation via HTTP in Oracle Document Management
Weaknesses CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title High Privilege Escalation via HTTP in Oracle Document Management
Weaknesses CWE-269
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle document Management And Collaboration
CPEs cpe:2.3:a:oracle:document_management_and_collaboration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle document Management And Collaboration
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Document Management And Collaboration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:23.679Z

Reserved: 2026-08-31T15:40:57.360Z

Link: CVE-2026-83453

cve-icon Vulnrichment

Updated: 2026-09-17T12:58:32.878Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:54.057

Modified: 2026-09-17T14:17:44.373

Link: CVE-2026-83453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:00:08Z

Weaknesses
  • CWE-269

    Improper Privilege Management