ZeroHour

CVE-2026-87150

moderate

Authenticated Takeover in Oracle EBS Bills of Material Setup Workbench

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87150 is a high-severity (CVSS 8.8) vulnerability in the Setup Workbench component of Oracle Bills of Material, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged, authenticated attacker who has network access to the EBS instance over HTTP. A successful attack allows the attacker to fully take over Oracle Bills of Material, with high impact on the confidentiality, integrity, and availability of that component's data. Any organization running an affected 12.2.x release with the Bills of Material product exposed to users is affected, including instances reachable from untrusted or internal networks. No public proof-of-concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no indication of active exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87150 to all EBS 12.2.3-12.2.15 environments running Bills of Material, prioritizing any instance reachable over HTTP from untrusted networks. Restrict network access to EBS web entry points (firewall/VPN), audit low-privileged accounts for anomalous activity against Setup Workbench, and verify the patch level of all 12.2.x middleware and database tiers.

Affected
Oracle E-Business Suite Bills of Material (Setup Workbench component)12.2.3-12.2.15
Estimated exposure
moderate≈ several thousand internet-exposed EBS instances, plus tens of thousands of internal enterprise deployments (estimate) — Oracle EBS 12.2 is an on-premises enterprise product deployed at thousands of organizations, of which only a small fraction (typically low thousands per internet scan data of exposed EBS login pages) are directly internet-facing, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.