Vulnerability in Oracle E-Business Suite Affecting Maintenance and Repair Operations
CVE-2026-83425

8.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83425?

A vulnerability has been identified in Oracle's Complex Maintenance, Repair and Overhaul application within the Oracle E-Business Suite. This issue allows a low-privileged attacker with network access via HTTP to exploit the system, potentially leading to unauthorized access to sensitive data. The vulnerability primarily affects versions 12.2.12 through 12.2.15, and while it targets the Maintenance and Repair operations, there is a significant risk of broader impact on other Oracle products. Successful exploitation can result in unauthorized data access and partial denial of service, emphasizing the importance of prompt remediation to secure enterprise data.

Affected Version(s)

Oracle Complex Maintenance, Repair and Overhaul 12.2.12 <= 12.2.15

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.