CVE-2026-87153
moderateAuthenticated data manipulation flaw in Oracle Product Hub (E-Business Suite)
CVE-2026-87153 is a high-severity (CVSS 3.1: 8.1) vulnerability in the Internal Operations component of Oracle Product Hub, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is exploitable over HTTP by a low-privileged (authenticated) attacker with network access to the EBS instance, and Oracle describes it as easily exploitable. A successful attack allows the attacker to create, delete, or modify critical Product Hub data, or to read all Product Hub-accessible data, with high impact to both confidentiality and integrity (availability is not affected). Any organization running an affected E-Business Suite 12.2.x version with the Product Hub module licensed and deployed is affected, particularly if the instance is reachable over a network by ordinary application users. No public proof-of-concept is known and the CVE is not on the CISA KEV list, so exploitation in the wild is not currently indicated.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87153 to all E-Business Suite 12.2.3–12.2.15 environments running Product Hub. Restrict HTTP access to EBS application tiers so only authenticated, authorized users can reach Product Hub responsibilities, and enforce least-privilege roles since exploitation requires only a low-privileged account. Review audit and FND logs for unexpected creation, deletion, or modification of item/product master data by low-privilege accounts, and rotate credentials for any accounts showing anomalous activity.
| Oracle Product Hub (Oracle E-Business Suite), Internal Operations component | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.