Impact
The Oracle Shipping Execution component of Oracle E‑Business Suite contains a flaw that permits an attacker with high privileges and network access over HTTP to fully take control of the application. The vulnerability can be exploited for complete compromise of confidentiality, integrity, and availability, effectively allowing a takeover of the Shipping Execution service. The weakness is categorized as a privilege escalation and authentication bypass (CWE‑269, CWE‑284, CWE‑306).
Affected Systems
Vulnerable installations are the Oracle Shipping Execution product within Oracle E‑Business Suite versions 12.2.12 through 12.2.15. All deployments of these versions that have not applied the August 2026 CPU update are susceptible. The affected component is the Internal Operations module of Shipping Execution.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 indicates a high impact rating, while the EPSS score of less than 1% suggests that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. However, an attacker who gains network connectivity to the service and has or can obtain high‑privileged accounts can exploit the flaw to seize control. The same HTTP entry point that is used for legitimate traffic also serves as the attack surface.
OpenCVE Enrichment