Description
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker with high privileges and network access via HTTP to compromise Oracle Cost Management, resulting in a full takeover of the application. It is an easily exploitable remote vulnerability that can affect Confidentiality, Integrity, and Availability, reflected in a CVSS 3.1 Base Score of 7.2.

Affected Systems

Affected systems are Oracle Corporation’s Oracle Cost Management product within Oracle E‑Business Suite, specifically the Cost Planning component. Versions from 12.2.3 through 12.2.15 are impacted, while later releases are not listed as affected.

Risk and Exploitability

The risk is high because the attack vector is network‑based over HTTP and exploitation would grant the attacker complete control of the application. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score indicates a high likelihood of severe impact if exploited.

Generated by OpenCVE AI on August 19, 2026 at 11:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch for Oracle Cost Management as detailed in Oracle’s August 2026 security alert.
  • Restrict HTTP access to the Cost Planning component to trusted IP addresses or disable the component until a patch is applied.
  • Monitor application and network logs for suspicious HTTP requests targeting the Cost Planning endpoint and investigate any anomalies promptly.

Generated by OpenCVE AI on August 19, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Oracle Cost Management Remote Takeover via HTTP Vulnerability
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle cost Management
CPEs cpe:2.3:a:oracle:cost_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle cost Management
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Cost Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:26:46.926Z

Reserved: 2026-07-14T14:54:48.740Z

Link: CVE-2026-62540

cve-icon Vulnrichment

Updated: 2026-08-26T13:48:52.951Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-18T21:17:06.603

Modified: 2026-08-26T16:16:32.480

Link: CVE-2026-62540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:30:04Z

Weaknesses