CVE-2026-87168
moderateAuthenticated Data Tampering Flaw in Oracle EBS Purchasing G-Invoicing
CVE-2026-87168 is a vulnerability in the G-Invoicing component of Oracle Purchasing, part of Oracle E-Business Suite, affecting releases 12.2.10 through 12.2.15. A low-privileged (authenticated) attacker with HTTP network access to the EBS instance can exploit it easily (CVSS 3.1: 8.1, AV:N/AC:L/PR:L) to compromise Oracle Purchasing. Successful attacks allow unauthorized creation, deletion, or modification of critical data (or all Oracle Purchasing-accessible data) as well as unauthorized read access to that data; availability is not impacted. Primarily at risk are enterprises and government-linked organizations running affected 12.2.x releases with the G-Invoicing component exposed to internal or external network users. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87168 to all EBS 12.2.10-12.2.15 environments running Oracle Purchasing/G-Invoicing, and verify the patch landed on every node. Restrict HTTP access to the EBS application tier (VPN/IP allowlisting) and enforce least-privilege roles for accounts that touch Purchasing. Review audit trails for unexpected creation, deletion, or modification of Purchasing and G-Invoicing records by low-privileged accounts.
| Oracle E-Business Suite Purchasing (G-Invoicing component) | 12.2.10-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.