Description
Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Financials (International) accessible data as well as unauthorized read access to a subset of Oracle Public Sector Financials (International) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-08-18
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Authorization component of Oracle Public Sector Financials (International) permits a low‑privilege attacker with network access over HTTP to bypass authorization controls. The flaw enables unauthorized inserts, updates, or deletes on the database, unauthorized reading of restricted data, and the ability to trigger a partial denial of service. This improper access control weakness directly impacts confidentiality, integrity, and availability as quantified by a CVSS 3.1 base score of 6.3.

Affected Systems

The vulnerability affects Oracle Public Sector Financials (International) versions 12.2.3 through 12.2.15, a component of Oracle E‑Business Suite commonly deployed by government entities managing public sector financial data.

Risk and Exploitability

With a CVSS 3.1 score of 6.3, the vulnerability is rated moderate severity. An attacker only needs low privileges and network access via HTTP, and no user interaction is required, making exploitation straightforward. The EPSS score is 0.00189, indicating a very low probability of exploitation, and the Oracle advisory describes the flaw as easily exploitable. The vulnerability is not listed in CISA’s KEV catalogue. Successful exploitation can lead to unauthorized data manipulation, data disclosure, and service interruption, threatening the trust and operational stability of impacted organizations.

Generated by OpenCVE AI on August 21, 2026 at 12:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and deploy the Oracle Security Update for Public Sector Financials (International) referenced in the August 2026 Security Advisory to patch the authorization flaw.
  • Restrict HTTP traffic to the application using firewall rules or network segmentation, limiting access to trusted internal networks and reducing the attack surface for low‑privilege attackers.
  • Enforce strict role‑based access controls, ensuring that only authorized users can perform updates, inserts, or deletes on sensitive data, and regularly review privilege assignments to maintain least privilege.

Generated by OpenCVE AI on August 21, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Enabling Unauthorized Data Modification, Read, and Partial Denial of Service in Oracle Public Sector Financials

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Financials (International) accessible data as well as unauthorized read access to a subset of Oracle Public Sector Financials (International) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle public Sector Financials
CPEs cpe:2.3:a:oracle:public_sector_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Financials
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Public Sector Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:17.294Z

Reserved: 2026-07-08T15:51:55.615Z

Link: CVE-2026-61139

cve-icon Vulnrichment

Updated: 2026-08-19T12:12:59.530Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:54.417

Modified: 2026-08-31T15:47:59.143

Link: CVE-2026-61139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:15:05Z

Weaknesses