Impact
A flaw in the access control logic of Oracle Customers Online's Internal Operations component permits an attacker with a low‑privilege network presence over HTTP to create, delete, modify, or read critical records. The vulnerability, identified as CWE‑284, directly impacts confidentiality and integrity, allowing full unauthorized access to any data available through Customers Online. The CVSS v3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) assigns a base score of 8.1.
Affected Systems
Affected are Oracle Customers Online versions 12.2.3 through 12.2.15 within Oracle E‑Business Suite. The advisory references the July 2026 CPU, where Oracle released a fix for these releases.
Risk and Exploitability
While the EPSS score is below 1%, suggesting a low probability of exploitation, the CVSS score indicates high severity, and the vulnerability is not yet in the CISA KEV catalog. An attacker only requires low‑privilege credentials and HTTP reach, making the attack straightforward for anyone with network access to the application. The lack of remote user interface and the dependency on low‑privilege accounts means exploitation is relatively easy for insiders or compromised internal users.
OpenCVE Enrichment