PatchSiren cyber security CVE debrief
CVE-2026-83490 Oracle Corporation CVE debrief
A vulnerability in Oracle iRecruitment of Oracle E-Business Suite (component: Internal Operations) has been identified. The supported versions affected are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle iRecruitment. While the vulnerability is in Oracle iRecruitment, attacks may significantly impact additional products (scope change). Successful attacks can result in unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data as well as unauthorized update, insert or delete access to some of Oracle iRecruitment accessible data.
- Vendor
- Oracle Corporation
- Product
- Oracle iRecruitment
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-21
Who should care
Defenders responsible for Oracle E-Business Suite and iRecruitment systems, as well as those managing network access and data security, should assess exposure and prioritize remediation.
Why it matters
Defenders should prioritize verifying exposure of Oracle iRecruitment versions 12.2.3-12.2.15 and assessing potential impacts due to the high CVSS score and potential for data breaches and system compromise.
- Potential unauthorized access to critical data
- Possible complete access to all Oracle iRecruitment accessible data
- Unauthorized update, insert or delete access to some Oracle iRecruitment data
- Scope change impacting additional products
Technical summary
The vulnerability in Oracle iRecruitment has a CVSS 3.1 Base Score of 8.5 (Confidentiality and Integrity impacts). The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N). This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle iRecruitment, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data as well as unauthorized update, insert or delete access to some of Oracle iRecruitment accessible data.
Defensive priority
Defenders should prioritize verifying exposure of Oracle iRecruitment versions 12.2.3-12.2.15 and assessing the potential impact on connected systems.
Recommended defensive actions
- Verify Oracle iRecruitment versions 12.2.3-12.2.15 are not in use or are patched
- Assess network exposure and restrict access to Oracle iRecruitment
- Monitor for unauthorized access or modifications to Oracle iRecruitment data
- Review and update incident response plans to address potential scope changes
- Perform vulnerability scanning to identify exposed systems
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, its impacts, and affected versions. Oracle's security alert page may contain additional details. Defenders should verify the exposure of Oracle iRecruitment versions 12.2.3-12.2.15 and assess potential impacts due to the high CVSS score and potential for data breaches and system compromise. Evidence is limited to CVE and NVD details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-83490 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-83490
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-83490 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-83490
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.