{
  "cve": "CVE-2026-83440",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[12.2.3,12.2.15]"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "Oracle Product Hub",
          "source": "cna",
          "vendor": "Oracle Corporation"
        },
        "product": "product_hub",
        "vendor": "oracle"
      }
    ],
    "created": "2026-09-16T06:15:07.044885+00:00",
    "title": "High‑Privilege Exploitation of Oracle Product Hub Over HTTP",
    "updated": "2026-09-20T07:30:17.515052+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$product_hub"
    ]
  },
  "epss": {
    "score": 0.00453
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-09-15T20:05:36.013000+00:00",
    "description": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.2,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/83xxx/CVE-2026-83440.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-17T13:00:24.641000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$product_hub"
    ],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-09-15T20:18:52.637000+00:00",
    "description": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.2,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-83440.json",
    "references": [
      "https://www.oracle.com/security-alerts/cspusep2026.html"
    ],
    "title": null,
    "updated": "2026-09-22T19:06:41.333000+00:00",
    "vendors": [
      "oracle",
      "oracle$PRODUCT$product_hub"
    ],
    "weaknesses": [
      "CWE-269"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-09-15T20:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "oracle",
              "oracle$PRODUCT$product_hub"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "oracle",
                "oracle$PRODUCT$product_hub"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://www.oracle.com/security-alerts/cspusep2026.html"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 7.2,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "7f483c1a-8abc-4aa6-bed9-987d627995ac"
      },
      {
        "created": "2026-09-16T20:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "High-Privilege HTTP Exploit of Oracle Product Hub Leading to Full Compromise",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-284",
                "CWE-285"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "27e3e819-37b4-49d3-bc5e-7cdefc236d34"
      },
      {
        "created": "2026-09-17T14:30:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "CWE-269"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "1a857b61-8af4-45f2-9bbc-8a89512db6df"
      },
      {
        "created": "2026-09-18T15:00:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "High-Privilege HTTP Exploit of Oracle Product Hub Leading to Full Compromise"
            },
            "type": "title"
          },
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-284",
                "CWE-285"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "f697ef72-d4e1-450e-883d-f7f382bfd9dd"
      },
      {
        "created": "2026-09-20T07:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "High‑Privilege Exploitation of Oracle Product Hub Over HTTP",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "f2b60952-1084-429d-8ec1-be697d3d6f9e"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "created": {
      "data": "2026-09-15T20:05:36.013000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 7.2,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00453
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.oracle.com/security-alerts/cspusep2026.html"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "High‑Privilege Exploitation of Oracle Product Hub Over HTTP",
      "provider": "enrichment"
    },
    "updated": {
      "data": "2026-09-20T07:30:17.515052+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "oracle",
        "oracle$PRODUCT$product_hub"
      ],
      "providers": [
        "mitre",
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-269"
      ],
      "providers": [
        "nvd",
        "vulnrichment"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-09-15T20:05:36.013000+00:00",
    "description": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-09-17T12:58:54.519000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/83xxx/CVE-2026-83440.json",
    "weaknesses": [
      "CWE-269"
    ]
  }
}