ZeroHour

CVE-2026-87154

moderate

Authenticated Data Tampering Flaw in Oracle E-Business Suite Product Hub 12.2

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

An easily exploitable authorization flaw in the Internal Operations component of Oracle Product Hub, part of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful exploitation gives the attacker unauthorized creation, deletion, or modification of critical data, or complete read access to all Oracle Product Hub accessible data — high impact on both confidentiality and integrity (CVSS 3.1 base score 8.1), though availability is not affected. Supported E-Business Suite releases 12.2.3 through 12.2.15 are affected. No public proof of concept is known and the issue is not on the CISA Known Exploited Vulnerabilities catalog, so there is no evidence of exploitation in the wild at this time.

What to do: Apply the Oracle Critical Patch Update containing the fix for CVE-2026-87154 to every EBS 12.2.3-12.2.15 environment running Product Hub. Restrict HTTP access to EBS internal operations endpoints (VPN or IP allowlisting) and audit low-privileged application accounts for unexpected Product Hub activity, including unauthorized data creation, deletion, or modification.

Affected
Oracle E-Business Suite — Product Hub (Internal Operations component)12.2.3-12.2.15
Estimated exposure
moderate≈ several thousand organizations (subset of the roughly 10,000+ internet-reachable Oracle EBS instances) — Oracle EBS is deployed by tens of thousands of enterprises worldwide and public internet scans routinely show thousands of exposed EBS web endpoints, of which only a subset license Product Hub and run an affected 12.2.x release.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.