Description
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improperly enforced access control flaw in Oracle Product Hub, affecting the Outbound Data component, that allows a low‑privileged attacker with network access via HTTP to gain full control of the application. The CVSS 3.1 base score of 8.8 indicates severe confidentiality, integrity and availability impacts, and successful exploitation would result in a complete takeover of Oracle Product Hub.

Affected Systems

Oracle Product Hub, a component of Oracle E‑Business Suite, is impacted for supported versions from 12.2.3 through 12.2.15.

Risk and Exploitability

The attack vector is network‑based and requires only low privileges, making it highly exploitable from any location that can reach the HTTP service. The EPSS score of <1% indicates a very low probability of exploitation in the wild, but the high CVSS score and the ability to compromise the entire hub still present a critical risk for exposed deployments.

Generated by OpenCVE AI on August 22, 2026 at 04:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Product Hub patch that addresses the access control flaw as soon as it becomes available.
  • Restrict HTTP access to the hub to trusted networks or users by configuring firewalls, VPNs, or host‑based controls.
  • Monitor application and web‑server logs for anomalous requests and enable intrusion detection or alerting rules to detect potential exploitation attempts.

Generated by OpenCVE AI on August 22, 2026 at 04:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Access Control Bypass in Oracle Product Hub

Sat, 22 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title HTTP Exploit Allows Low-Privilege Compromise of Oracle Product Hub
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title HTTP Exploit Allows Low-Privilege Compromise of Oracle Product Hub
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle product Hub
CPEs cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Hub
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Product Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T03:55:51.082Z

Reserved: 2026-08-04T22:06:34.605Z

Link: CVE-2026-70918

cve-icon Vulnrichment

Updated: 2026-08-22T02:28:33.233Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:49.583

Modified: 2026-08-28T14:45:18.037

Link: CVE-2026-70918

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T04:45:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function