CVE-2026-87163
moderateAuthenticated Takeover Flaw in Oracle E-Business Suite Purchasing 12.2.3-12.2.15
CVE-2026-87163 is a high-severity (CVSS 8.8) vulnerability in the Oracle Purchasing module of Oracle E-Business Suite, affecting supported releases 12.2.3 through 12.2.15. It is triggered remotely over HTTP by an attacker who already holds a low-privileged account on the EBS instance, requiring no user interaction or special conditions. A successful attack lets the attacker fully compromise Oracle Purchasing, with high impact on the confidentiality, integrity, and availability of that component. Any organization running EBS 12.2.3-12.2.15 with the Purchasing module reachable over the network is affected, particularly instances exposed to the internet. No public proof-of-concept exists and no exploitation in the wild has been reported; the flaw is not on the CISA KEV list.
What to do: Apply the Oracle Critical Patch Update that delivers the fix for CVE-2026-87163 to all EBS 12.2.3-12.2.15 environments running Purchasing, prioritizing any instance reachable over the network. Restrict HTTP access to EBS via VPN/IP allowlisting so that low-privileged self-service and supplier accounts cannot reach vulnerable endpoints from untrusted networks. Review user account provisioning in Purchasing and audit logs for anomalous activity by low-privilege accounts as an interim detection measure.
| Oracle Purchasing (Oracle E-Business Suite) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.