Description
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

Oracle Mobile Application Server is vulnerable to a flaw in the MWA Terminal Server component that allows an attacker who can reach the server over a TCP network connection to execute code without authentication. The weakness directly compromises confidentiality, integrity, and availability of the server application, effectively enabling an attacker to take full control of the Oracle Mobile Application Server. The vulnerability is identified as an Authentication Failure (CWE‑287) and an Authorization Failure (CWE‑306).

Affected Systems

Oracle Mobile Application Server, versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite.

Risk and Exploitability

This critical flaw has a CVSS v3.1 Base Score of 9.8. The EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis, yet the required conditions are minimal—a network accessible TCP connection and no authentication. The vulnerability is not currently listed in the CISA KEV catalogue. An exploited instance would result in a complete takeover of the application server, providing full administrative rights to the attacker.

Generated by OpenCVE AI on September 18, 2026 at 15:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses CVE-2026-83462 for Oracle Mobile Application Server 12.2.3 through 12.2.15
  • Disable or restrict the TCP port used by the MWA Terminal Server to limit exposure to trusted networks
  • Configure firewall rules to block unsolicited inbound connections targeting the server and monitor connection attempts for suspicious activity

Generated by OpenCVE AI on September 18, 2026 at 15:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Mobile Application Server

Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Mobile Application Server

Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle mobile Application Server
CPEs cpe:2.3:a:oracle:mobile_application_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mobile Application Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Mobile Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:34.648Z

Reserved: 2026-08-31T15:40:57.360Z

Link: CVE-2026-83462

cve-icon Vulnrichment

Updated: 2026-09-15T22:44:35.971Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:55.030

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:15:06Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function