Description
Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle iRecruitment executes to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iRecruitment accessible data as well as unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data manipulation and confidentiality compromise
Action: Assess Impact
AI Analysis

Impact

This vulnerability allows an unauthenticated attacker who has physical access to the communication segment connected to the Oracle iRecruitment server to compromise the application. Successful exploitation enables the attacker to create, delete, modify, or otherwise access critical data managed by Oracle iRecruitment. The impact is a direct loss of confidentiality and integrity, as described by the CVSS vector that indicates high disclosure and integrity impacts with no availability effect.

Affected Systems

The affected products are Oracle Corporation’s Oracle iRecruitment component of Oracle E‑Business Suite, specifically the Internal Operations module. Versions 12.2.3 through 12.2.15 are documented as vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 6.8 reflects moderate severity, while the EPSS score of < 1% indicates that, historically, the likelihood of exploitation is low and the vulnerability is not listed in the CISA KEV catalog. The described attack vector is adjacent network (AV:A), requiring the attacker to reach the server’s communication segment, indicating a local or near‑local threat. If the attacker can access this segment, the vulnerability can be leveraged to perform unauthorized data modification or access.

Generated by OpenCVE AI on September 18, 2026 at 17:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any official Oracle patch or update released for the affected Oracle iRecruitment versions as soon as it becomes available.
  • Restrict physical access to the network segment that connects the Oracle iRecruitment server to authorized personnel only.
  • Review and tighten access control policies and user permissions for the Oracle iRecruitment Internal Operations component to ensure no excessive privileges exist.

Generated by OpenCVE AI on September 18, 2026 at 17:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Physical Network Segment Access in Oracle iRecruitment

Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Physical Network Segment Access in Oracle iRecruitment
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle iRecruitment executes to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iRecruitment accessible data as well as unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle irecruitment
CPEs cpe:2.3:a:oracle:irecruitment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle irecruitment
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Irecruitment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:46.005Z

Reserved: 2026-08-31T15:40:57.362Z

Link: CVE-2026-83491

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:56.930

Modified: 2026-09-22T19:05:30.883

Link: CVE-2026-83491

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:45:11Z

Weaknesses