CVE-2026-87164
nicheLow-privilege takeover flaw in Oracle Banking Branch Reports component (14.5–14.9)
CVE-2026-87164 is a difficult-to-exploit vulnerability in the Reports component of Oracle Banking Branch, part of Oracle Financial Services Applications, affecting versions 14.5.0.0.0 through 14.9.0.0.0. A low-privileged attacker with network access via HTTP must trick a legitimate user into interacting with a crafted request (e.g., a social-engineering lure), after which a successful attack compromises Oracle Banking Branch and, due to a scope change, can significantly impact additional products beyond the vulnerable component. Successful exploitation can result in full takeover of Oracle Banking Branch with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 8.0, high). The affected population is limited to financial institutions running the Oracle Banking Branch product in the affected version range. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update (CPU) remediation for CVE-2026-87164 to all Oracle Banking Branch instances on 14.5.0.0.0–14.9.0.0.0, and verify no affected installs exist in test or DR environments. Because exploitation requires a low-privileged account plus user interaction, enforce least-privilege review of branch/reporting user accounts, restrict HTTP access to the application to trusted networks, and coach staff against clicking attacker-supplied links. Audit logs for anomalous activity by low-privileged accounts against the Reports component around the patch window.
| Oracle Banking Branch (Oracle Financial Services Applications, Reports component) | 14.5.0.0.0 - 14.9.0.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Branch. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Branch, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Banking Branch. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.