Vulnerability in Oracle E-Business Suite's Maintenance and Repair Product
CVE-2026-83445

8.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83445?

A security flaw exists in the Oracle Complex Maintenance, Repair and Overhaul component of the Oracle E-Business Suite. This vulnerability allows a low privileged attacker with network access via HTTPS to potentially take control of the affected system. Attackers exploiting this vulnerability can compromise sensitive information, impacting confidentiality, integrity, and availability. Oracle has released an advisory detailing the affected versions and recommended mitigations to safeguard against potential attacks.

Affected Version(s)

Oracle Complex Maintenance, Repair and Overhaul 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.