ZeroHour

CVE-2026-87163

moderate

Authenticated Takeover Flaw in Oracle E-Business Suite Purchasing 12.2.3-12.2.15

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87163 is a high-severity (CVSS 8.8) vulnerability in the Oracle Purchasing module of Oracle E-Business Suite, affecting supported releases 12.2.3 through 12.2.15. It is triggered remotely over HTTP by an attacker who already holds a low-privileged account on the EBS instance, requiring no user interaction or special conditions. A successful attack lets the attacker fully compromise Oracle Purchasing, with high impact on the confidentiality, integrity, and availability of that component. Any organization running EBS 12.2.3-12.2.15 with the Purchasing module reachable over the network is affected, particularly instances exposed to the internet. No public proof-of-concept exists and no exploitation in the wild has been reported; the flaw is not on the CISA KEV list.

What to do: Apply the Oracle Critical Patch Update that delivers the fix for CVE-2026-87163 to all EBS 12.2.3-12.2.15 environments running Purchasing, prioritizing any instance reachable over the network. Restrict HTTP access to EBS via VPN/IP allowlisting so that low-privileged self-service and supplier accounts cannot reach vulnerable endpoints from untrusted networks. Review user account provisioning in Purchasing and audit logs for anomalous activity by low-privilege accounts as an interim detection measure.

Affected
Oracle Purchasing (Oracle E-Business Suite)12.2.3-12.2.15
Estimated exposure
moderate≈ low thousands of internet-exposed EBS instances globally, with an unknown subset running Purchasing — Oracle E-Business Suite is enterprise software deployed by thousands of organizations, and public internet scans (e.g., Shodan/Censys) have historically shown only a few thousand internet-facing EBS web endpoints, of which only some…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.