ZeroHour

CVE-2026-87158

moderate

Authenticated Data Exposure in Oracle E-Business Suite Order Management ECC v16

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

Oracle E-Business Suite's Order Management product contains an easily exploitable vulnerability in its Enterprise Command Center (ECC) component, affecting supported version V16. A low-privileged attacker with network access via HTTP — meaning any authenticated user with minimal rights, no user interaction required — can compromise Oracle Order Management. Successful exploitation yields unauthorized read access to critical data or complete access to all Order Management accessible data, plus unauthorized update, insert, or delete access to some of that data; availability is not impacted. The flaw is rated High severity with a CVSS 3.1 base score of 7.1 (C:H/I:L/A:N). It is not listed in CISA's KEV catalog, no public proof-of-concept is known, and there is no evidence of in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw in ECC V16 as soon as it is available in your patch cycle. Until patched, restrict HTTP access to Enterprise Command Center endpoints to trusted networks or VPN and enforce least-privilege on EBS accounts that can reach them. Review ECC and Order Management audit logs for anomalous data queries or unauthorized changes made by low-privileged users.

Affected
Oracle E-Business Suite Order Management (Enterprise Command Center component)
Estimated exposure
moderate≈ low thousands of installations (subset of E-Business Suite sites running Order Management ECC v16) — Public internet scans (Shodan/Censys) typically show a few thousand internet-exposed Oracle E-Business Suite instances, and Enterprise Command Center is an optional add-on deployed on only a fraction of those, so the affected ECC v16…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Enterprise Command Center). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Order Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.