CVE-2026-83165
8.8Oracle · Oracle Customer Interaction History
A vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite allows a low privileged, network-based attacker to achieve a full system takeover.
Executive summary
Oracle Customer Interaction History is susceptible to a high-severity vulnerability that allows an authenticated attacker to gain full control over the application.
Vulnerability
This vulnerability resides in the User Interface component and allows an attacker with low-level privileges to perform a full takeover of the application via HTTPS. The flaw is easily exploitable over the network without requiring user interaction.
Business impact
Successful exploitation of this vulnerability results in a total compromise of the Oracle Customer Interaction History application, leading to potential unauthorized access to sensitive customer data and disruption of business operations. With a CVSS score of 8.8, this flaw represents a significant risk to confidentiality, integrity, and availability, necessitating immediate attention to prevent unauthorized system control.
Remediation
Immediate Action: Review the latest Oracle Security Alert advisory at https://www.oracle.com/security-alerts/cspusep2026.html and apply the corresponding patch for your environment.
Proactive Monitoring: Monitor application access logs for unusual patterns, particularly unauthorized requests targeting the User Interface component or elevated privilege activities from standard user accounts.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall to filter traffic directed at the E-Business Suite instance until the security update is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for a full application takeover, organizations must prioritize the identification of affected Oracle E-Business Suite instances. Security teams should move quickly to apply the vendor-supplied security patches as soon as they become available to eliminate the risk of unauthorized access and system compromise.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Oracle Advisory Vendor advisory