Description
Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Onboarding Batch Processes). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks of this vulnerability can result in takeover of Oracle Banking Origination. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

A flaw in the Onboarding Batch Processes component of Oracle Banking Origination under Oracle Financial Services Applications permits a low‑privileged attacker with network access to an HTTP endpoint to compromise the system. If exploited successfully, an attacker can gain full control of Oracle Banking Origination, causing total loss of confidentiality, integrity, and availability of the application.

Affected Systems

Oracle Banking Origination versions 14.5.0.0.0 through 14.9.0.0.0 are affected. The vulnerability touches the Onboarding Batch Processes component and is reachable via standard HTTP traffic exposed to the network.

Risk and Exploitability

The vulnerability has a CVSS 3.1 base score of 7.5, indicating substantial impact. The EPSS score is below 1%, implying a very low probability of exploitation at this time. It is not listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request from a low‑privilege user within the network, exploiting insufficient access controls to the batch process interface.

Generated by OpenCVE AI on September 17, 2026 at 23:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses the Onboarding Batch Processes vulnerability as detailed in the Oracle Security Alert 2026.1.0.
  • Restrict the exposed HTTP interface of the Onboarding Batch Processes so that only accounts with privileged roles can reach it. Consider disabling the interface on non‑production nodes.
  • Implement network segmentation or firewall rules to limit inbound HTTP traffic to Oracle Banking Origination from trusted IP ranges, reducing the attack surface for potential local or remote attackers.

Generated by OpenCVE AI on September 17, 2026 at 23:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via HTTP in Oracle Banking Origination Onboarding Batch Processes
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via HTTP in Oracle Banking Origination Onboarding Batch Processes
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Onboarding Batch Processes). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks of this vulnerability can result in takeover of Oracle Banking Origination. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle banking Origination
CPEs cpe:2.3:a:oracle:banking_origination:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle banking Origination
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Banking Origination
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:22.295Z

Reserved: 2026-08-31T15:40:57.362Z

Link: CVE-2026-83489

cve-icon Vulnrichment

Updated: 2026-09-17T12:58:00.634Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:56.707

Modified: 2026-09-17T14:17:45.530

Link: CVE-2026-83489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:15:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management