ZeroHour

CVE-2026-87166

moderate

Authenticated Access-Control Flaw Exposes Oracle Purchasing Data in EBS 12.2

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87166 is a high-severity (CVSS 3.1 base 8.1) vulnerability in the Oracle Purchasing product of Oracle E-Business Suite, affecting supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit it easily, using a valid low-level account to compromise Oracle Purchasing. Successful attacks allow unauthorized creation, deletion, or modification of critical Purchasing data, as well as unauthorized read access to critical data or all Oracle Purchasing-accessible data; availability is not impacted per the CVSS vector (C:H/I:H/A:N). Any organization running E-Business Suite 12.2 with the Oracle Purchasing module reachable over HTTP by internal or external users is affected. No public proof of concept is known and the flaw is not in the CISA KEV catalog, but it was addressed in Oracle's April 2026 Critical Patch Update.

What to do: Apply the Oracle Critical Patch Update (April 2026) that remediates this flaw to all E-Business Suite 12.2.3–12.2.15 environments running Oracle Purchasing, as EBS security patches are cumulative within the 12.2 codeline. Restrict HTTP reachability to EBS so only authenticated, authorized users on trusted networks or VPN can access it. Review Purchasing audit logs for unexpected data creation, modification, deletion, or read activity by low-privilege accounts.

Affected
Oracle Purchasing (Oracle E-Business Suite)12.2.3-12.2.15
Estimated exposure
moderate≈1,000–10,000 internet-exposed EBS instances; tens of thousands of organizational deployments overall — Oracle E-Business Suite is deployed at roughly ten thousand enterprises worldwide, public internet scans historically show a few thousand exposed EBS web endpoints, and Purchasing is a core financial module present in most EBS deployments.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.