Description
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Oracle Product Hub component of Oracle E‑Business Suite contains an easily exploitable flaw that permits a low‑privileged attacker with network access to HTTP endpoints to compromise the application. Successful exploitation can lead to full takeover of Oracle Product Hub, resulting in total loss of confidentiality, integrity, and availability of the system. The vulnerability is reflected in a CVSS v3.1 base score of 8.8, indicating high severity across all three core security categories.

Affected Systems

Affected installations are Oracle Product Hub releases 12.2.3 through 12.2.15, all currently supported. These versions include the Internal Operations component that is susceptible to the flaw. The vulnerability applies to all variants of the product within this version window.

Risk and Exploitability

With a CVSS score of 8.8 the vulnerability poses a serious threat. The EPSS score is lower than 1 %, suggesting that, by and large, exploits are not yet widely deployed, and the issue is not listed in CISA’s KEV catalog. The attack vector is straightforward—an adversary only needs network connectivity to an HTTP service, and no privileged credentials are required. The combination of a low attack effort and complete compromise makes the risk significant for exposed systems.

Generated by OpenCVE AI on September 17, 2026 at 23:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy Oracle’s official patch or upgrade to a non‑affected release of Oracle Product Hub immediately.
  • Restrict HTTP access to the Product Hub by implementing firewall rules, IP whitelisting, or VPN access to limit exposure to trusted networks.
  • Enable continuous monitoring of application logs and web traffic to detect suspicious activity and respond promptly to any anomalous events.

Generated by OpenCVE AI on September 17, 2026 at 23:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Product Hub via HTTP

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Product Hub via HTTP
Weaknesses CWE-94

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle product Hub
CPEs cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Hub
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Product Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:24.308Z

Reserved: 2026-08-31T15:40:57.359Z

Link: CVE-2026-83444

cve-icon Vulnrichment

Updated: 2026-09-17T12:58:47.403Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:53.067

Modified: 2026-09-22T19:06:13.203

Link: CVE-2026-83444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:15:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')