ZeroHour

CVE-2026-87126

moderate

Low-Privilege Data Exposure and Partial DoS in Oracle E-Business Suite Report Manager

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87126 is a vulnerability in the Reports Security component of Oracle Report Manager, part of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can trigger the flaw, which Oracle rates as easily exploitable with no user interaction required. A successful attack lets the attacker read critical data or all Oracle Report Manager accessible data, and to cause a partial denial of service of the component; integrity is not impacted. Any organization running E-Business Suite 12.2.3-12.2.15 with Report Manager exposed to users or networks is affected, particularly deployments reachable from the internet or broad internal networks. The issue is not on CISA's KEV list and no public proof-of-concept or observed exploitation is known, but an authenticated account is the only real barrier.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87126 to all E-Business Suite 12.2.3-12.2.15 environments running Report Manager, prioritizing any instance whose HTTP endpoints are internet-facing. Restrict network access to EBS web tiers (segmentation, VPN, WAF rules) and audit low-privileged accounts with access to reporting functions. Review Report Manager access logs and report-generation history around and before the patch date for signs of unauthorized data reads or abuse-driven report failures.

Affected
Oracle Report Manager (Oracle E-Business Suite, component: Reports Security)12.2.3-12.2.15
Estimated exposure
moderateLikely thousands of Report Manager-capable installations worldwide, out of an estimated low tens of thousands of internet-reachable Oracle E-Business Suite… — Public internet scans (Shodan/Censys-style counts of exposed EBS login pages) have historically shown on the order of 10,000-20,000 internet-facing E-Business Suite deployments, and Oracle Report Manager is a financial-reporting component…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Reports Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Report Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Report Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Report Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.