Description
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Inventory Costing). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in Oracle Cost Management’s Inventory Costing component that allows an attacker who has network access via HTTP to exploit a high‑privilege access control weakness. Once leveraged, the attacker can fully take over the application, modify or exfiltrate cost data, and disrupt service operation. The vulnerability is identified as CWE‑284 (Broken Access Control). The CVSS 3.1 base score of 7.2 reflects moderate severity but indicates that the impact is comprehensive when successful.

Affected Systems

Affected systems are the Oracle Cost Management product within Oracle E‑Business Suite, specifically the Inventory Costing module. Versions 12.2.3 through 12.2.15 are impacted.

Risk and Exploitability

The CVSS score of 7.2, combined with an EPSS score of less than 1%, suggests low exploitation probability in the wild, though the risk is heightened for environments that expose Cost Management over HTTP and maintain accounts with high privileges. The vulnerability is not listed in the CISA KEV catalog, so no confirmed widespread attacks are reported, but the potential impact warrants prompt remediation. The likely attack path involves an attacker using remote HTTP traffic to a Cost Management endpoint, leveraging their elevated credentials to bypass access controls and gain total control of the application.

Generated by OpenCVE AI on August 4, 2026 at 02:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for Oracle Cost Management to all affected installations.
  • Disable or strictly limit HTTP exposure of the Cost Management service, or confine it to a protected network segment such as a VPN or firewalled zone.
  • Enforce least‑privilege by ensuring only designated accounts possess high‑privilege roles within Cost Management and regularly audit assignment of those roles.
  • Monitor HTTP request logs and audit trails for anomalous activity from high‑privileged accounts and configure alerts for suspicious behavior.

Generated by OpenCVE AI on August 4, 2026 at 02:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title High‑Privilege HTTP Exploit in Oracle Cost Management Leading to Full Compromise

Thu, 30 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title High‑Privilege HTTP Exploit in Oracle Cost Management Leading to Full Compromise

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title High-Privilege Remote Exploitation in Oracle Cost Management
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Remote Exploitation in Oracle Cost Management
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Inventory Costing). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle cost Management
CPEs cpe:2.3:a:oracle:cost_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle cost Management
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Cost Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:50:25.139Z

Reserved: 2026-07-08T15:51:55.608Z

Link: CVE-2026-61027

cve-icon Vulnrichment

Updated: 2026-07-24T14:50:13.532Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:34.150

Modified: 2026-08-04T17:19:01.707

Link: CVE-2026-61027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses