Skip to content
OracleCVE-2026-83159

Applications DBA: takeover via ADPatch

High7.8CVE-2026-83159 · Published Sep 15, 2026 · updated Sep 17, 2026

Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Oracle advisory

Affected versions

PackageAffectedFixed in
Applications DBA
Product
>= 12.2.3, <= 12.2.15No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-284

More Oracle advisories

All Oracle
Advisory
Oracle GraalVM for JDK: takeover via Compiler
High8.1Sep 15
Oracle GraalVM for JDK: data tampering via Compiler
High7.0Sep 15
Oracle GraalVM for JDK: takeover via Compiler
High8.1Sep 15
Oracle VM VirtualBox: flaw in Core
Low3.2Sep 15
Oracle VM VirtualBox: denial of service via Core
Medium6.0Sep 15
Oracle GraalVM: takeover via Compiler
High8.1Sep 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.