ZeroHour

CVE-2026-87156

moderate

Low-Privilege Data Access Flaw in Oracle E-Business Suite Product Hub 12.2

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87156 is a vulnerability in the Internal Operations component of Oracle Product Hub within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, requiring no user interaction. A successful attack can expose critical data or grant complete read access to all Oracle Product Hub data, as well as unauthorized update, insert, and delete access to some of that data. Organizations running affected E-Business Suite 12.2 releases with Product Hub are at risk, particularly where end users have accounts with minimal privileges. The flaw carries a CVSS 3.1 base score of 7.1; no public proof of concept or known in-the-wild exploitation has been reported, and it is not on the CISA KEV list.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87156 to all E-Business Suite 12.2 environments running Product Hub. Review which low-privilege EBS accounts can reach Product Hub Internal Operations functions over HTTP and restrict or revoke unnecessary access; consider blocking internet exposure of EBS self-service/internal URLs. Audit Product Hub data access logs for unexpected reads or data modifications by low-privilege accounts to rule out prior compromise.

Affected
Oracle E-Business Suite Product Hub (Internal Operations component)12.2.3-12.2.15
Estimated exposure
moderatelikely low thousands of enterprise E-Business Suite deployments running Product Hub — Oracle E-Business Suite is estimated to run at tens of thousands of organizations worldwide, with only a subset licensed for Product Hub and a smaller subset running affected 12.2.x releases, so this is a rough order-of-magnitude estimate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible data as well as unauthorized update, insert or delete access to some of Oracle Product Hub accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.