Description
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle Public Sector Financials that allows an attacker with low privileged access to exploit the system over the network via HTTP. Successful exploitation can result in complete takeover of the application, compromising confidentiality, integrity, and availability of all data processed by the system.

Affected Systems

Oracle Public Sector Financials is affected for versions 12.2.3 through 12.2.15. The vulnerability is present in the Internal Operations component of the Oracle E‑Business Suite.

Risk and Exploitability

The CVSS score of 7.5 classifies this as a high severity flaw, while the EPSS score of less than 1 % indicates a low probability of prior exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Because the attack vector is network‑based and requires only low privilege, an attacker who can reach the HTTP endpoint can perform the exploit without user interaction or privileged credentials.

Generated by OpenCVE AI on August 4, 2026 at 02:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Public Sector Financials as outlined in the Oracle CPU July 2026 advisory
  • Restrict HTTP access to the Public Sector Financials instance to trusted networks and enforce least‑privilege user accounts
  • Implement additional audit logging and monitor for abnormal access patterns to detect potential exploitation attempts

Generated by OpenCVE AI on August 4, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Exploit Allows Full Compromise of Oracle Public Sector Financials

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover via Low‑Privilege HTTP Access in Oracle Public Sector Financials

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover via Low‑Privilege HTTP Access in Oracle Public Sector Financials
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle public Sector Financials
CPEs cpe:2.3:a:oracle:public_sector_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Financials
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Public Sector Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:02:04.525Z

Reserved: 2026-07-08T15:51:55.602Z

Link: CVE-2026-60931

cve-icon Vulnrichment

Updated: 2026-07-24T17:01:57.955Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:28.113

Modified: 2026-07-29T15:59:41.297

Link: CVE-2026-60931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function