ZeroHour

CVE-2026-87162

niche

Authenticated Takeover Flaw in Oracle EBS Contract Lifecycle Management for Public Sector

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87162 is a high-severity vulnerability (CVSS 3.1 base score 8.8) in the Award/PO component of Oracle Contract Lifecycle Management for Public Sector, a module of Oracle E-Business Suite. It is easily exploitable by a low-privileged, authenticated attacker who has network access to the application via HTTP. Successful exploitation can result in a complete takeover of the Oracle Contract Lifecycle Management for Public Sector application, with high impact on confidentiality, integrity, and availability. Only versions 12.2.13 through 12.2.15 are listed as affected. There is no known public proof of concept, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported as of this analysis.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87162 to all E-Business Suite instances running 12.2.13-12.2.15 of Contract Lifecycle Management for Public Sector, and verify the fixed version in Oracle's advisory. Until patched, restrict HTTP access to the CLM module to trusted networks or VPN, and audit low-privilege account activity in the Award/PO component for anomalous requests. Review least-privilege role assignments in EBS to limit the pool of accounts capable of triggering the flaw.

Affected
Oracle Contract Lifecycle Management for Public Sector (Oracle E-Business Suite, component: Award/PO)12.2.13-12.2.15
Estimated exposure
nichelikely hundreds to low thousands of public-sector EBS installations (no public install counts for this module) — Oracle E-Business Suite is widely deployed in large enterprises and government, but the Public Sector Contract Lifecycle Management module is a specialized government-facing component with no published install or active-deployment counts,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award/PO). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public Sector. Successful attacks of this vulnerability can result in takeover of Oracle Contract Lifecycle Management for Public Sector. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.