Skip to content
OracleCVE-2026-83170

Oracle One-to-One Fulfillment: takeover via Documents

High8.0CVE-2026-83170 · Published Sep 15, 2026 · updated Sep 17, 2026

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle One-to-One Fulfillment executes to compromise Oracle One-to-One Fulfillment. Successful attacks of this vulnerability can result in takeover of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Oracle advisory

Affected versions

PackageAffectedFixed in
Oracle One-to-One Fulfillment
Product
>= 12.2.3, <= 12.2.15No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-269

More Oracle advisories

All Oracle
Advisory
Oracle GraalVM for JDK: takeover via Compiler
High8.1Sep 15
Oracle GraalVM for JDK: data tampering via Compiler
High7.0Sep 15
Oracle GraalVM for JDK: takeover via Compiler
High8.1Sep 15
Oracle VM VirtualBox: flaw in Core
Low3.2Sep 15
Oracle VM VirtualBox: denial of service via Core
Medium6.0Sep 15
Oracle GraalVM: takeover via Compiler
High8.1Sep 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.