ZeroHour

CVE-2026-87160

moderate

Authenticated Data-Theft Flaw in Oracle E-Business Suite HRMS (India) 12.2.3-12.2.15

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87160 is an easily exploitable broken-access-control vulnerability in the Internal Operations component of Oracle HRMS (India), a localization module of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. A remote attacker with only low-privileged (valid application user) credentials and network access over HTTPS can exploit it to gain unauthorized read access to critical data — or complete access to all Oracle HRMS (India) accessible data — as well as unauthorized update, insert, and delete access to some of that data. The flaw has no user interaction requirement and no availability impact, carrying a CVSS 3.1 base score of 7.1 (high). Organizations running E-Business Suite 12.2 with the India HRMS localization exposed to untrusted networks or with large internal user populations are at greatest risk. There is no known public proof-of-concept, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating no known in-the-wild exploitation to date.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-87160 to all Oracle E-Business Suite 12.2.3-12.2.15 environments running the HRMS (India) module, prioritizing any instance reachable over the internet or by broad internal user bases. Restrict HTTPS access to EBS behind VPN/IP allowlisting and review least-privilege role assignments for low-privileged HRMS users. Finally, audit HRMS India data access and change logs for unauthorized reads or modifications that could indicate earlier exploitation.

Affected
Oracle HRMS (India) (Oracle E-Business Suite, component: Internal Operations)12.2.3 - 12.2.15
Estimated exposure
moderatelikely low thousands of installations worldwide (thousands of internet-exposed EBS hosts, with HRMS India localization used on a subset) — Internet-wide scans (Shodan/Censys and ERP-security research) typically surface on the order of tens of thousands of internet-facing Oracle E-Business Suite instances, and the India HRMS localization is deployed on only a fraction of those…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle HRMS (India). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (India) accessible data as well as unauthorized update, insert or delete access to some of Oracle HRMS (India) accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.