Description
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Role Based Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Hub accessible data as well as unauthorized read access to a subset of Oracle Product Hub accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Hub. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Role Based Security component of Oracle Product Hub. An attacker who is a low‑privileged user and can reach the Product Hub over HTTP can exploit this flaw to update, insert or delete data, read data not normally accessible, and force the service into a partial denial of service. The weakness is an improper access control (CWE‑284) that permits operations beyond the intended permissions. Successful exploitation compromises confidentiality, integrity and availability of the Product Hub data and functions.

Affected Systems

Oracle Product Hub, versions 12.2.3 through 12.2.15. The flaw is present on all supported releases within this range and can affect any installations that expose the Product Hub services to untrusted networks.

Risk and Exploitability

The CVSS score of 6.3 indicates medium severity. Because the attack requires only network access over HTTP and low privileges, the EPSS score is very low, under 1 %, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Even with a low exploitation probability, the potential impact on business data and operations warrants timely remediation. The likely attack path involves an attacker sending crafted HTTP requests that gain elevated permissions within the Product Hub service, leading to unauthorized data changes or a partial service outage.

Generated by OpenCVE AI on August 4, 2026 at 16:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Product Hub to a version newer than 12.2.15 to apply the vendor‑issued fix
  • Place the Product Hub behind a firewall or use network segmentation to limit HTTP access to trusted hosts only
  • Review and tighten Role Based Security configurations to ensure only authorized users can perform update, insert, or delete operations

Generated by OpenCVE AI on August 4, 2026 at 16:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Oracle Product Hub Role‑Based Security Access Control Bypass

Sun, 02 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Oracle Product Hub Role‑Based Security Access Control Bypass

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Role‑Based Security Bypass in Oracle Product Hub Leading to Data Modification and Partial Service Disruption

Mon, 27 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Role‑Based Security Bypass in Oracle Product Hub Leading to Data Modification and Partial Service Disruption

Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Role Based Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Hub accessible data as well as unauthorized read access to a subset of Oracle Product Hub accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Hub. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle product Hub
CPEs cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Hub
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Product Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:06:18.268Z

Reserved: 2026-07-08T15:52:20.744Z

Link: CVE-2026-61275

cve-icon Vulnrichment

Updated: 2026-07-22T15:05:39.500Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses