Description
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the internal operations component of Oracle Product Hub and allows an attacker with low privileges and network access over HTTP to bypass authentication and take complete control of the application. The result is loss of confidentiality, integrity, and availability because the attacker can access, modify, or delete data and disrupt services. This weakness is manifested through improper privilege management (CWE-269), authentication bypass (CWE-287), and missing authentication checks (CWE-306).

Affected Systems

Affected systems are Oracle Product Hub, a component of Oracle E‑Business Suite, for versions 12.2.3 through 12.2.15. No other product releases are listed as affected in the current advisory.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates high severity. The EPSS score is below 1%, suggesting that exploitation is currently considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. Likely attack conditions involve a low‑privileged attacker able to reach the Product Hub over HTTP, possibly using an unsecured or mis‑configured endpoint that does not enforce proper authentication. Consequently, the risk profile remains high, but the chance of real‑world exploitation is low as of the time of analysis.

Generated by OpenCVE AI on August 4, 2026 at 00:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the Oracle CPU July 2026 advisory and apply any released patches for Oracle Product Hub.
  • Restrict HTTP access to Oracle Product Hub by permitting only trusted internal hosts and enforcing network segmentation to reduce the attack.
  • Ensure all accounts interacting with Oracle Product Hub adhere to strong authentication and least privilege principles, disabling any default or unused administrative accounts.
  • Monitor and audit HTTP access logs for anomalous activity and unauthorized authentication attempts.

Generated by OpenCVE AI on August 4, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Remote Authentication Bypass Leading to Full Compromise of Oracle Product Hub via HTTP

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Remote Authentication Bypass Leading to Full Compromise of Oracle Product Hub via HTTP

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Access Leading to Full Compromise of Oracle Product Hub via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access Leading to Full Compromise of Oracle Product Hub via HTTP

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle product Hub
CPEs cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Hub
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Product Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:55:43.401Z

Reserved: 2026-07-08T15:52:20.746Z

Link: CVE-2026-61311

cve-icon Vulnrichment

Updated: 2026-07-22T18:00:11.500Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function