Unauthorized Access Vulnerability in Oracle E-Business Suite Mobile Application Server
CVE-2026-83463

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83463?

A vulnerability has been identified in the Oracle Mobile Application Server component of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. An unauthenticated attacker with access to the physical communication segment connected to the hardware could exploit this vulnerability to gain control of the Oracle Mobile Application Server. The complexity associated with this vulnerability makes it particularly challenging to exploit, but successful attempts can lead to a complete takeover of the server, posing significant risks to data confidentiality, integrity, and availability.

Affected Version(s)

Oracle Mobile Application Server 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.