ZeroHour

CVE-2026-87164

niche

Low-privilege takeover flaw in Oracle Banking Branch Reports component (14.5–14.9)

CVSS 3.1
8.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87164 is a difficult-to-exploit vulnerability in the Reports component of Oracle Banking Branch, part of Oracle Financial Services Applications, affecting versions 14.5.0.0.0 through 14.9.0.0.0. A low-privileged attacker with network access via HTTP must trick a legitimate user into interacting with a crafted request (e.g., a social-engineering lure), after which a successful attack compromises Oracle Banking Branch and, due to a scope change, can significantly impact additional products beyond the vulnerable component. Successful exploitation can result in full takeover of Oracle Banking Branch with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 8.0, high). The affected population is limited to financial institutions running the Oracle Banking Branch product in the affected version range. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update (CPU) remediation for CVE-2026-87164 to all Oracle Banking Branch instances on 14.5.0.0.0–14.9.0.0.0, and verify no affected installs exist in test or DR environments. Because exploitation requires a low-privileged account plus user interaction, enforce least-privilege review of branch/reporting user accounts, restrict HTTP access to the application to trusted networks, and coach staff against clicking attacker-supplied links. Audit logs for anomalous activity by low-privileged accounts against the Reports component around the patch window.

Affected
Oracle Banking Branch (Oracle Financial Services Applications, Reports component)14.5.0.0.0 - 14.9.0.0.0
Estimated exposure
nichelikely low hundreds of installations worldwide (rough order of magnitude, no public count) — Oracle Banking Branch is licensed enterprise banking software deployed per financial institution, typically on internal networks behind bank perimeters, so no public active-install or internet-scan telemetry exists; the estimate is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Branch. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Branch, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Banking Branch. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.