Vulnerability in Oracle E-Business Suite Mobile Application Server
CVE-2026-83465

8.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83465?

A vulnerability in the Oracle Mobile Application Server within the Oracle E-Business Suite allows an unauthenticated attacker to exploit the server through HTTP. This vulnerability impacts several supported versions and may lead to unauthorized access that can cause the server to hang or crash repeatedly, resulting in a denial-of-service condition. Furthermore, an attacker could gain unauthorized access to modify or delete data managed by the Mobile Application Server, significantly affecting the integrity and availability of the system. The attack approach necessitates human interaction from another individual, posing a unique challenge for mitigation.

Affected Version(s)

Oracle Mobile Application Server 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.