ZeroHour

CVE-2026-87127

niche

Authenticated Data Exposure in Oracle E-Business Suite Purchasing (G-Invoicing)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87127 is a high-severity (CVSS 7.7) vulnerability in the G-Invoicing component of Oracle Purchasing, part of Oracle E-Business Suite, affecting versions 12.2.10 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, requiring no user interaction. Successful attacks result in unauthorized access to critical data or complete access to all Oracle Purchasing accessible data, with impacts limited to confidentiality; because of a scope change, other products in the environment may also be affected. Organizations running affected EBS 12.2 releases with the Purchasing/G-Invoicing module are exposed wherever the EBS web tier is reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87127 to all E-Business Suite 12.2 environments running 12.2.10-12.2.15. Restrict HTTP access to the EBS/G-Invoicing endpoints to trusted networks and VPN users, and enforce least-privilege roles for accounts that can reach the module. Review audit logs for unusual read access by low-privileged accounts, since the flaw exfiltrates data without leaving integrity or availability changes.

Affected
Oracle Purchasing (Oracle E-Business Suite, G-Invoicing component)12.2.10-12.2.15
Estimated exposure
nichelikely hundreds to low thousands of deployments worldwide (subset of EBS 12.2 sites running G-Invoicing) — Oracle publishes no install counts, but while E-Business Suite runs on tens of thousands of instances overall, the G-Invoicing component is deployed mainly by U.S. federal agencies and their trading partners, sharply narrowing the affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. While the vulnerability is in Oracle Purchasing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.