ZeroHour

CVE-2026-87155

moderate

Low-Privilege Takeover Flaw in Oracle E-Business Suite Product Hub (12.2.3-12.2.15)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87155 is a high-severity (CVSS 8.8) vulnerability in the Internal Operations component of Oracle Product Hub, part of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged attacker who has network access to the EBS environment via HTTP and a valid low-level account. A successful attack allows the attacker to fully compromise Oracle Product Hub, with high impact on confidentiality, integrity, and availability — effectively a takeover of the product. Organizations running affected EBS 12.2 releases with the Product Hub module are at risk, particularly where self-service or external-facing HTTP endpoints are reachable. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so exploitation is not currently observed in the wild.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-87155 to all EBS 12.2.3-12.2.15 environments running Product Hub. Restrict HTTP access to EBS so the Product Hub/Internal Operations endpoints are not reachable from untrusted networks, and enforce least-privilege on low-privileged application accounts. Review audit logs for anomalous activity by low-privilege users against Product Hub, such as unexpected privilege escalation or data access, that could indicate an attempted compromise.

Affected
Oracle E-Business Suite / Product Hub (Internal Operations component)12.2.3-12.2.15
Estimated exposure
moderate≈ thousands of internet-reachable Oracle EBS deployments; subset licensed/running Product Hub — Oracle EBS is on-premises enterprise software deployed at roughly tens of thousands of organizations worldwide, with public internet scans routinely showing thousands of exposed EBS HTTP endpoints; Product Hub usage is a module-level…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.