CVE-2026-87150
moderateAuthenticated Takeover in Oracle EBS Bills of Material Setup Workbench
CVE-2026-87150 is a high-severity (CVSS 8.8) vulnerability in the Setup Workbench component of Oracle Bills of Material, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged, authenticated attacker who has network access to the EBS instance over HTTP. A successful attack allows the attacker to fully take over Oracle Bills of Material, with high impact on the confidentiality, integrity, and availability of that component's data. Any organization running an affected 12.2.x release with the Bills of Material product exposed to users is affected, including instances reachable from untrusted or internal networks. No public proof-of-concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no indication of active exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87150 to all EBS 12.2.3-12.2.15 environments running Bills of Material, prioritizing any instance reachable over HTTP from untrusted networks. Restrict network access to EBS web entry points (firewall/VPN), audit low-privileged accounts for anomalous activity against Setup Workbench, and verify the patch level of all 12.2.x middleware and database tiers.
| Oracle E-Business Suite Bills of Material (Setup Workbench component) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.