ZeroHour

CVE-2026-87165

niche

Authenticated Remote Takeover in Oracle CLM for Public Sector (E-Business Suite) V16

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Oracle Contract Lifecycle Management for Public Sector, a module of Oracle E-Business Suite (component: ECC For Award and IDV), contains an easily exploitable vulnerability affecting supported version V16. A remote attacker with only low-privileged network access via HTTP can exploit it to fully compromise the CLM for Public Sector application. Successful attacks result in complete takeover, with high impact on the confidentiality, integrity, and availability of the affected software (CVSS 3.1 base score 8.8). Organizations running this public-sector procurement module on E-Business Suite V16 are affected. No public proof-of-concept exists and the flaw is not on the CISA KEV catalog, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-87165 to all Contract Lifecycle Management for Public Sector V16 deployments. Restrict HTTP/network access to the EBS CLM and ECC endpoints to trusted users and networks, and enforce least privilege so low-privileged accounts cannot reach sensitive components. Review audit logs for anomalous activity by low-privilege accounts against ECC for Award and IDV functionality.

Affected
Oracle Contract Lifecycle Management for Public Sector (Oracle E-Business Suite, component: ECC For Award and IDV)
Estimated exposure
nichelikely hundreds to low thousands of public-sector E-Business Suite deployments (order-of-magnitude estimate) — Oracle E-Business Suite is widely deployed at large enterprises and government agencies, but the Public Sector CLM module with the ECC for Award and IDV component is a specialized procurement add-on used by a small subset of those…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: ECC For Award and IDV). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public Sector. Successful attacks of this vulnerability can result in takeover of Oracle Contract Lifecycle Management for Public Sector. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.