ZeroHour

CVE-2026-87149

niche

Low-Privilege Data Access Flaw in Oracle EBS CLM for Public Sector (Award/PO)

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

A high-severity (CVSS 3.1 base 7.1) flaw in the Award/PO component of Oracle Contract Lifecycle Management for Public Sector, part of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to read all data accessible to the module — including critical data — and to update, insert, or delete some of that data. Oracle rates the vulnerability as easily exploitable with no user interaction required, but exploitation requires a valid low-privileged account on the EBS instance, so the main risk is privilege escalation and data exposure by insiders or attackers using stolen credentials. Affected deployments are Oracle E-Business Suite 12.2.8 through 12.2.15 running this Public Sector module. The impact is limited to confidentiality (high) and integrity (low); availability is not affected. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and no exploitation in the wild has been reported.

What to do: Apply the fix from Oracle's latest Critical Patch Update for E-Business Suite if you run versions 12.2.8-12.2.15 with the Public Sector Contract Lifecycle Management module. Restrict HTTP/network access to the EBS instance to trusted users and VPN ranges, and enforce least-privilege roles for module users. Review audit logs around Award/PO functionality for unexpected data reads or modifications by low-privileged accounts.

Affected
Oracle Contract Lifecycle Management for Public Sector (Oracle E-Business Suite, component: Award/PO)12.2.8-12.2.15
Estimated exposure
nichehundreds to low thousands of installations (subset of Oracle E-Business Suite deployments running the Public Sector CLM module) — Public internet scans typically show only a few thousand internet-reachable Oracle E-Business Suite instances globally, and this government-focused contracting module is a specialized subset of that install base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award/PO). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public Sector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Contract Lifecycle Management for Public Sector accessible data as well as unauthorized update, insert or delete access to some of Oracle Contract Lifecycle Management for Public Sector accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.