CVE-2026-87127
nicheAuthenticated Data Exposure in Oracle E-Business Suite Purchasing (G-Invoicing)
CVE-2026-87127 is a high-severity (CVSS 7.7) vulnerability in the G-Invoicing component of Oracle Purchasing, part of Oracle E-Business Suite, affecting versions 12.2.10 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, requiring no user interaction. Successful attacks result in unauthorized access to critical data or complete access to all Oracle Purchasing accessible data, with impacts limited to confidentiality; because of a scope change, other products in the environment may also be affected. Organizations running affected EBS 12.2 releases with the Purchasing/G-Invoicing module are exposed wherever the EBS web tier is reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no exploitation has been reported to date.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87127 to all E-Business Suite 12.2 environments running 12.2.10-12.2.15. Restrict HTTP access to the EBS/G-Invoicing endpoints to trusted networks and VPN users, and enforce least-privilege roles for accounts that can reach the module. Review audit logs for unusual read access by low-privileged accounts, since the flaw exfiltrates data without leaving integrity or availability changes.
| Oracle Purchasing (Oracle E-Business Suite, G-Invoicing component) | 12.2.10-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. While the vulnerability is in Oracle Purchasing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.