Description
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker with network access can exploit a flaw in the Oracle Public Sector Financials Internal Operations component to gain full control of the application. The vulnerability is remotely exploitable over HTTP and can compromise confidentiality, integrity and availability in a single successful attack, as reflected by a CVSS 3.1 Base Score of 8.8.

Affected Systems

Oracle Public Sector Financials, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV and no publicly disclosed exploit code is known, but the attack vector is likely over the public internet via an unauthenticated HTTP request to the vulnerable component. Successful exploitation could result in a full takeover of the application, exposing all data and functions.

Generated by OpenCVE AI on August 4, 2026 at 00:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for Oracle Public Sector Financials if it is available.
  • If a patch is not yet published, restrict HTTP access to the Internal Operations component to trusted IP ranges or internal networks only.
  • Enable detailed logging and continuously monitor for anomalous authentication or privilege–escalation attempts.
  • Consider upgrading to a non‑vulnerable version of the product if patching is not feasible.

Generated by OpenCVE AI on August 4, 2026 at 00:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Exploit Allows Remote Takeover of Oracle Public Sector Financials

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Exploit Allows Remote Takeover of Oracle Public Sector Financials

Mon, 27 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Public Sector Financials

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Public Sector Financials

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle public Sector Financials
CPEs cpe:2.3:a:oracle:public_sector_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Financials
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Public Sector Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T16:33:11.446Z

Reserved: 2026-07-14T14:54:48.734Z

Link: CVE-2026-62478

cve-icon Vulnrichment

Updated: 2026-07-22T16:33:08.029Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function