PatchSiren cyber security CVE debrief
CVE-2026-83485 Oracle Corporation CVE debrief
The CVE-2026-83485 vulnerability affects Oracle Product Hub's Item Catalog component in versions 12.2.3-12.2.15. This easily exploitable vulnerability allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. Defenders should prioritize verifying exposure in Oracle Product Hub deployments, especially those with low-privileged network access via HTTP, and apply Oracle's security patches for affected versions.
- Vendor
- Oracle Corporation
- Product
- Oracle Product Hub
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-21
Who should care
Defenders responsible for Oracle Product Hub deployments, especially those with low-privileged network access via HTTP, should assess exposure and prioritize verification and remediation efforts.
Why it matters
Defenders should prioritize verifying exposure in Oracle Product Hub deployments, especially those with low-privileged network access via HTTP, due to a vulnerability that could lead to unauthorized data access and potential impact on additional products.
- Potential unauthorized access to critical data or complete access to all Oracle Product Hub accessible data.
- Possible impact on additional products beyond Oracle Product Hub.
- Need for verification of exposure in Oracle Product Hub deployments with low-privileged network access via HTTP.
- Priority for applying Oracle's security patches for affected versions.
Technical summary
A vulnerability in Oracle Product Hub (component: Item Catalog) allows a low-privileged attacker with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. The vulnerability affects versions 12.2.3-12.2.15 of Oracle Product Hub. Defenders should prioritize verifying exposure in Oracle Product Hub deployments, especially those with low-privileged network access via HTTP, and apply Oracle's security patches for affected versions.
Defensive priority
Defenders should prioritize verifying exposure in Oracle Product Hub deployments, especially those with low-privileged network access via HTTP.
Recommended defensive actions
- Verify Oracle Product Hub deployments for version 12.2.3-12.2.15 and assess exposure to low-privileged network access via HTTP.
- Review and apply Oracle's security patches for affected versions.
- Monitor network access and authentication mechanisms to prevent unauthorized access.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Oracle Product Hub, its impact, and affected versions. The vulnerability is in the Item Catalog component of Oracle Product Hub, affecting versions 12.2.3-12.2.15. The CVE record was published on 2026-09-15T20:18:56.257Z and has not been modified since then. Defenders should verify exposure in Oracle Product Hub deployments with low-privileged network access via HTTP and review Oracle's security patches.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-83485 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-83485
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-83485 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-83485
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.