Description
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Oracle Applications Framework component known as Web Utilities allows a high‑privileged attacker with network access over HTTP to fully compromise the framework. The flaw is an access control failure (CWE‑284) that can be easily exploited. Successful exploitation destroys confidentiality, integrity and availability, effectively enabling a complete takeover of the affected system and potentially impacting additional Oracle products due to scope change.

Affected Systems

The flaw affects Oracle Applications Framework users of Oracle E‑Business Suite. Supported versions from 12.2.8 through 12.2.15 are vulnerable. The vulnerability resides exclusively in the Web Utilities component of this product.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical severity. Although the EPSS score is below 1%, the risk remains high because a remote attacker could leverage the flaw if they possess high‑level privileges and network reachability. The flaw is not yet listed in the CISA KEV catalog, but its impact warrants immediate attention. Exploitation requires network access to the exposed HTTP interface and the presence of a privileged account; no special conditions beyond these are specified.

Generated by OpenCVE AI on August 4, 2026 at 15:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU‑Jul‑2026 patch that addresses Oracle Applications Framework versions 12.2.8 through 12.2.15
  • If a patch cannot be applied immediately, block external HTTP traffic to the Web Utilities interface using firewalls or VPNs, allowing access only from trusted administrative hosts
  • Configure strict privilege controls and minimize exposed Web Utilities services, ensuring only properly authenticated users can access the application

Generated by OpenCVE AI on August 4, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation and System Takeover in Oracle Applications Framework Web Utilities

Sun, 02 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation and System Takeover in Oracle Applications Framework Web Utilities

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title High-Privilege Exploit in Oracle Applications Framework Web Utilities

Mon, 27 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title High-Privilege Exploit in Oracle Applications Framework Web Utilities

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Framework
CPEs cpe:2.3:a:oracle:applications_framework:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Framework
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T14:01:39.868Z

Reserved: 2026-07-14T14:54:48.740Z

Link: CVE-2026-62546

cve-icon Vulnrichment

Updated: 2026-07-22T14:01:36.247Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses