ZeroHour

CVE-2026-87152

moderate

Authenticated Data Tampering Flaw in Oracle E-Business Suite Installed Base

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87152 is an authorization flaw in the Create Item Instance component of Oracle Installed Base, a module of Oracle E-Business Suite versions 12.2.3 through 12.2.15. A remote attacker who already holds a low-privileged (valid minimally privileged) account can exploit it easily over HTTP without user interaction, and gain unauthorized ability to create, delete, or modify critical Installed Base data as well as read that data in full. Installed Base tracks serialized item instances (installed assets, service and repair history), so successful attacks could expose sensitive customer asset data and corrupt service records. Organizations running affected EBS 12.2.x releases with the Installed Base module exposed to network users are affected. No public proof-of-concept or in-the-wild exploitation is known, and the flaw is not on the CISA KEV list.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87152 to all E-Business Suite 12.2.3-12.2.15 environments running Installed Base. Restrict HTTP access to EBS so only authenticated, trusted networks or VPN users can reach it, and audit low-privilege accounts for excessive grants. Review Installed Base item-instance change history and audit logs for unauthorized creation, modification, or deletion of records by low-privileged users.

Affected
Oracle Installed Base (Oracle E-Business Suite), Create Item Instance component12.2.3-12.2.15
Estimated exposure
moderatelow-thousands of internet-reachable EBS instances; roughly tens of thousands of organizations run EBS 12.2, with an unknown subset licensing Installed Base — Oracle EBS is on-premises enterprise software with a customer base commonly estimated in the tens of thousands of organizations, of which public scan data historically shows only a few thousand EBS web endpoints exposed to the internet;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.