Impact
The vulnerability resides in the ADPatch component of the Oracle Applications DBA product, part of Oracle E‑Business Suite. It allows a low‑privileged attacker with network access via HTTP to gain full control of the database administration interface. The flaw results in confidentiality, integrity, and availability impacts, with a CVSS 3.1 base score of 8.8 indicating a high‑severity threat.
Affected Systems
Oracle Applications DBA versions 12.2.3 through 12.2.15 are affected. Users running any of these releases that expose the HTTP interface to the network must verify whether they have applied the July 2026 CPU patch. The affected product is the Oracle Applications DBA component ADPatch within the Oracle E‑Business Suite.
Risk and Exploitability
The high CVSS score of 8.8 reflects the potential for complete takeover, while the EPSS score of less than 1 % suggests that observed exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, requiring only network connectivity to the vulnerable HTTP endpoint and no elevated privileges, making it potentially exploitable by unauthenticated or low‑privileged users.
OpenCVE Enrichment