CVE-2026-87152
moderateAuthenticated Data Tampering Flaw in Oracle E-Business Suite Installed Base
CVE-2026-87152 is an authorization flaw in the Create Item Instance component of Oracle Installed Base, a module of Oracle E-Business Suite versions 12.2.3 through 12.2.15. A remote attacker who already holds a low-privileged (valid minimally privileged) account can exploit it easily over HTTP without user interaction, and gain unauthorized ability to create, delete, or modify critical Installed Base data as well as read that data in full. Installed Base tracks serialized item instances (installed assets, service and repair history), so successful attacks could expose sensitive customer asset data and corrupt service records. Organizations running affected EBS 12.2.x releases with the Installed Base module exposed to network users are affected. No public proof-of-concept or in-the-wild exploitation is known, and the flaw is not on the CISA KEV list.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87152 to all E-Business Suite 12.2.3-12.2.15 environments running Installed Base. Restrict HTTP access to EBS so only authenticated, trusted networks or VPN users can reach it, and audit low-privilege accounts for excessive grants. Review Installed Base item-instance change history and audit logs for unauthorized creation, modification, or deletion of records by low-privileged users.
| Oracle Installed Base (Oracle E-Business Suite), Create Item Instance component | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.