Description
Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Project Foundation executes to compromise Oracle Project Foundation. Successful attacks of this vulnerability can result in takeover of Oracle Project Foundation. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Project Foundation suffers an improper access control flaw that allows any user with a local login to the underlying infrastructure to gain administrative control over the application. The vulnerability enables a low‑privileged attacker to subvert confidentiality, integrity and availability, ultimately leading to a full takeover of the system.

Affected Systems

The affected vendor is Oracle Corporation, specifically Oracle Project Foundation within Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are impacted.

Risk and Exploitability

The CVSS v3.1 base score of 7.8 reflects high impact across all core security properties. The EPSS score of less than 1% indicates that, while exploitation is possible, it is currently considered uncommon. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires the attacker to already possess a local account with limited privileges; from there the flaw can be leveraged to elevate privileges and fully compromise the application.

Generated by OpenCVE AI on August 5, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Project Foundation patch or upgrade to a version beyond 12.2.15
  • Restrict local account privileges on the underlying infrastructure to enforce least privilege and remove unnecessary accounts
  • Implement log monitoring and intrusion detection to detect potential misuse of local accounts attempting to exploit the vulnerability

Generated by OpenCVE AI on August 5, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Local Account Compromise in Oracle Project Foundation

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Local Account Compromise in Oracle Project Foundation
Weaknesses CWE-284

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control Enables Local Takeover of Oracle Project Foundation

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Enables Local Takeover of Oracle Project Foundation
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Project Foundation executes to compromise Oracle Project Foundation. Successful attacks of this vulnerability can result in takeover of Oracle Project Foundation. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle project Foundation
CPEs cpe:2.3:a:oracle:project_foundation:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle project Foundation
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Project Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:01:26.223Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61090

cve-icon Vulnrichment

Updated: 2026-07-24T14:01:20.675Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management