Description
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Cost Planning component of Oracle 12.2.3 through 12.2.15 allows a high privileged attacker with network access through HTTP to fully compromise the application. The impact is significant, with confidentiality, integrity, and availability all affected, and the flaw is a CWE‑284 access control weakness that permits privilege escalation and takeover.

Affected Systems

Oracle Cost Management from Oracle Corporation, specifically the Cost Planning component; affected releases include 12.2.3 to 12.2.15.

Risk and Exploitability

The CVSS 3.1 base score of 6.6 indicates moderate severity, meaning a successful exploit would provide full confidentiality, integrity, and availability impacts. However, the vulnerability requires a high‑privileged attacker with direct HTTP network access and the EPSS score is below 1%, demonstrating a low probability of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog, which further underscores the lower risk rating. Attackers who meet the prerequisite conditions could coerce the application into executing administrative actions, effectively gaining control of the Cost Management system.

Generated by OpenCVE AI on August 4, 2026 at 15:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Oracle security patch for CVE-2026 advisory
  • Restrict HTTP access to the Oracle Cost Management interface to trusted IP ranges or VPNs
  • Enforce strict role‑based access control so that only users with legitimate high‑privilege rights can access Cost Planning functions

Generated by OpenCVE AI on August 4, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title High Privilege Access Control Violation in Oracle Cost Management Leads to Full Application Takeover

Sun, 02 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title High Privilege Access Control Violation in Oracle Cost Management Leads to Full Application Takeover

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Compromise via HTTP in Oracle Cost Management

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Compromise via HTTP in Oracle Cost Management

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle cost Management
CPEs cpe:2.3:a:oracle:cost_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle cost Management
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Cost Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:52:13.302Z

Reserved: 2026-07-08T15:52:20.747Z

Link: CVE-2026-61328

cve-icon Vulnrichment

Updated: 2026-07-22T17:52:09.204Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses