Description
Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an easily exploitable weakness in Oracle Yard Management that allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation results in full takeover, thereby compromising confidentiality, integrity, and availability of the Yard Management system. The weakness falls under improper access control or privilege escalation concerns, as the attacker can bypass intended permissions.

Affected Systems

Oracle Corporation’s Oracle Yard Management component of Oracle E-Business Suite is impacted. The affected releases are all versions from 12.2.6 through 12.2.15, inclusive.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 signals high severity, and the same vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) shows that a remote, low-privileged user can reach the flaw. EPSS is under 1%, indicating that hacking attempts are historically uncommon, and the flaw is not yet listed in the CISA KEV catalogue. Based on the description, it is inferred that a likely attack scenario involves an attacker discovering an exposed HTTP endpoint, sending a crafted request that exploits the underlying access control flaw, and executing arbitrary code or commands, thereby taking over the Yard Management instance.

Generated by OpenCVE AI on August 2, 2026 at 18:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or update provided by Oracle for the affected Oracle Yard Management releases as detailed in the July 2026 Oracle CPU.
  • Restrict HTTP access to the Oracle Yard Management server to a limited set of trusted IP addresses or VPN endpoints to reduce exposure.
  • Review and tighten user roles and permissions within Oracle Yard Management to ensure that low-privileged accounts do not have unintended access to sensitive functions.

Generated by OpenCVE AI on August 2, 2026 at 18:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title High-Impact Remote Access Vulnerability in Oracle Yard Management Allowing Low-Privileged Takeover
Weaknesses CWE-284
CWE-862

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit in Oracle Yard Management Leads to Takeover
Weaknesses CWE-269
CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit in Oracle Yard Management Leads to Takeover
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle yard Management
CPEs cpe:2.3:a:oracle:yard_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle yard Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Yard Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:31:19.567Z

Reserved: 2026-07-14T14:54:48.736Z

Link: CVE-2026-62496

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T19:00:04Z

Weaknesses