Description
Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle U.S. Federal Financials. Successful attacks of this vulnerability can result in takeover of Oracle U.S. Federal Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A network‑directed vulnerability in Oracle U.S. Federal Financials enables an attacker with low privileges on the local network to execute arbitrary code and gain complete control of the application. The weakness allows the attacker to bypass authentication checks and assume full administrative rights, thereby compromising confidentiality, integrity, and availability of all data processed by the system. The CVSS 3.1 score of 8.8 and vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H confirm the severity and ease of exploitation. This is a weak access control vulnerability, classified as CWE‑284.

Affected Systems

The vulnerability affects Oracle U.S. Federal Financials, part of Oracle E‑Business Suite’s Internal Operations component, for all supported releases from 12.2.3 through 12.2.15.

Risk and Exploitability

Exploitation requires only network access over HTTP from a low‑privileged position; no user interaction is needed. The lack of a publicly disclosed EPSS score and absence from the CISA KEV catalog mean that exploitation likelihood is uncertain, but the high CVSS score and straightforward attack path provide a strong incentive for adversaries. Organizations should assume the risk of compromise until a patch is applied.

Generated by OpenCVE AI on August 21, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle U.S. Federal Financials patch released in the advisory
  • Segment the application so that only trusted IPs can reach the HTTP endpoint or enclose the service behind a VPN
  • Enable comprehensive logging and monitor HTTP traffic for anomalous requests that may indicate exploitation attempts

Generated by OpenCVE AI on August 21, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle e-business Suite
CPEs cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*
Vendors & Products Oracle e-business Suite

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in Oracle U.S. Federal Financials
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle U.S. Federal Financials. Successful attacks of this vulnerability can result in takeover of Oracle U.S. Federal Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle u.s. Federal Financials
CPEs cpe:2.3:a:oracle:u.s._federal_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle u.s. Federal Financials
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle E-business Suite U.s. Federal Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:23:39.398Z

Reserved: 2026-07-08T15:52:20.747Z

Link: CVE-2026-61319

cve-icon Vulnrichment

Updated: 2026-08-24T15:13:04.352Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:59.960

Modified: 2026-09-03T16:14:25.110

Link: CVE-2026-61319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T11:30:04Z

Weaknesses