CVE-2026-87151
moderateAuthenticated Information Disclosure in Oracle EBS Bills of Material (Setup Workbench)
CVE-2026-87151 is a high-severity information disclosure vulnerability in the Setup Workbench component of Oracle Bills of Material, part of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP — for example, any authenticated EBS user with minimal permissions — can exploit the flaw without user interaction to read data beyond their normal authorization boundary. Because of a scope change, successful attacks not only expose Oracle Bills of Material data but can significantly impact additional E-Business Suite products, potentially yielding unauthorized access to critical business data or complete access to all data reachable through the Bills of Material module. The flaw carries a CVSS 3.1 base score of 7.7, driven entirely by high confidentiality impact. No public proof of concept exists and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no indication of in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that remediates this vulnerability to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances reachable over HTTP. Restrict EBS web endpoints to VPN or trusted networks so that low-privileged accounts cannot reach the Setup Workbench from the open internet. Review audit logs for anomalous data-access patterns by low-privilege users against Bills of Material / Setup Workbench functions, and check whether other EBS modules' data was accessed in a scope-change scenario.
| Oracle E-Business Suite (Oracle Bills of Material, Setup Workbench component) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.