Description
Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Takeover
Action: Immediate Patch
AI Analysis

Impact

The Oracle Contracts product in Oracle E‑Business Suite has a vulnerability that allows a low‑privileged attacker with network access over HTTP to compromise the system. Successful exploitation can lead to complete loss of confidentiality, integrity and availability of the application.

Affected Systems

Affected products are Oracle Contracts within Oracle E‑Business Suite, specifically versions 12.2.14 and 12.2.15. These are the only versions identified as vulnerable.

Risk and Exploitability

The CVSS base score is 8.8, indicating a high severity vulnerability. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild at this time. The vulnerability is not listed in the CISA KEV catalog. An attacker only requires a low level of privilege and no user interaction to exploit the flaw via HTTP, making the attack vector relatively straightforward for an adversary with network access.

Generated by OpenCVE AI on September 17, 2026 at 23:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available Oracle patch or upgrade Oracle Contracts to version 12.2.16 or later.
  • Restrict network access to the Oracle Contracts service, limiting exposure to trusted hosts only.
  • Follow Oracle’s security advisory linked in the official alert for additional mitigation guidance.

Generated by OpenCVE AI on September 17, 2026 at 23:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Attack Enables Full Oracle Contracts Takeover
Weaknesses CWE-284
CWE-287

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Attack Enables Full Oracle Contracts Takeover
Weaknesses CWE-284
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle contracts
CPEs cpe:2.3:a:oracle:contracts:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contracts
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Contracts
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:22.870Z

Reserved: 2026-08-31T15:40:57.361Z

Link: CVE-2026-83479

cve-icon Vulnrichment

Updated: 2026-09-17T12:58:15.342Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:55.587

Modified: 2026-09-17T14:17:45.000

Link: CVE-2026-83479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management