cve-2026-83118

HIGH CVSS 7.8 nvd
Description

Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Timeline
Published
2026-09-15
Last Modified
2026-09-17
CVSS Details
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 1.8 5.9 secalert_us@oracle.com
NVD metadata
NVD status
Deferred
Source identifier
secalert_us@oracle.com
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 7.8,
  "datePublished": "2026-09-15T20:18:22.157",
  "dateUpdated": "2026-09-17T13:16:49.163",
  "description": "Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA.  Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
  "id": "CVE-2026-83118",
  "raw": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Applications DBA",
            "vendor": "Oracle Corporation",
            "versions": [
              {
                "lessThanOrEqual": "12.2.15",
                "status": "affected",
                "version": "12.2.3",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secalert_us@oracle.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA.  Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)."
      }
    ],
    "id": "CVE-2026-83118",
    "lastModified": "2026-09-17T13:16:49.163",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secalert_us@oracle.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-83118",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T12:48:08.598554Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-15T20:18:22.157",
    "references": [
      {
        "source": "secalert_us@oracle.com",
        "url": "https://www.oracle.com/security-alerts/cspusep2026.html"
      }
    ],
    "sourceIdentifier": "secalert_us@oracle.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-269"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  },
  "severity": "HIGH",
  "source": "nvd",
  "title": "Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities)"
}
View JSON API Download JSON