Description
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in takeover of Oracle Scripting. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Scripting component in Oracle E‑Business Suite is vulnerable to an easily exploitable flaw. A low‑privileged attacker with network access can leverage the HTTP interface to bypass normal authorization checks and gain full control of the scripting environment. The impact includes complete compromise of the Oracle Scripting service, resulting in confidentiality, integrity, and availability loss. The weakness maps to improper access control, allowing attackers to elevate privileges within the application.

Affected Systems

Oracle Corporation’s Oracle Scripting product, part of Oracle E‑Business Suite’s Internal Operations component, is affected. The vulnerability exists in versions 12.2.3 through 12.2.15. System administrators should verify whether these corresponding releases are in use.

Risk and Exploitability

The CVSS v3.1 score of 8.8 indicates a high‑severity vulnerability that can be exploited over the network with a low attack complexity and requiring only local privileges. Although the EPSS score is not available and the flaw is not listed in the CISA KEV catalog, the lack of mitigation steps in the affected environment makes exploitation likely if the HTTP interface remains reachable from untrusted networks. The attack path does not require user interaction and can be performed remotely, highlighting the need for immediate remediation.

Generated by OpenCVE AI on August 21, 2026 at 12:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Scripting patch or upgrade to a version newer than 12.2.15.
  • Restrict HTTP access to the Oracle Scripting service by limiting inbound traffic to trusted networks or implementing firewall rules.
  • Review and tighten role‑based access controls within Oracle E‑Business Suite to ensure that low‑privileged users cannot invoke scripting functionality.
  • Monitor audit logs for anomalous scripting activity and investigate any unauthorized execution attempts.

Generated by OpenCVE AI on August 21, 2026 at 12:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Oracle Scripting HTTP Interface
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in takeover of Oracle Scripting. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle scripting
CPEs cpe:2.3:a:oracle:scripting:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle scripting
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Scripting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T14:04:32.317Z

Reserved: 2026-07-08T15:51:55.605Z

Link: CVE-2026-60976

cve-icon Vulnrichment

Updated: 2026-08-21T14:04:25.201Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:49.957

Modified: 2026-08-31T15:48:08.043

Link: CVE-2026-60976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:45:04Z

Weaknesses