Description
Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Application Takeover
Action: Immediate Patch
AI Analysis

Impact

A defect in Oracle Contracts permits an attacker who already possesses high‑privileged network credentials to bypass established authorization checks and assume full control of the application. The issue results in complete compromise of confidentiality, integrity, and availability and is identified as an elevation of privilege (CWE‑269). Successful exploitation enables the attacker to conduct unrestricted operations within Oracle Contracts, effectively taking over the system.

Affected Systems

Oracle Corporation’s Oracle Contracts product, part of Oracle E‑Business Suite, is affected for versions 12.2.14 through 12.2.15. Clients interacting over HTTP are exposed to the vulnerability.

Risk and Exploitability

The CVSS 3.1 base score of 7.2 indicates high severity. With an EPSS score below 1 %, widespread exploitation is currently unlikely, and the vulnerability is not catalogued in the CISA KEV directory. The attack vector assumes network access via HTTP, where an attacker sends crafted requests on behalf of a user who possesses high‑privileged credentials, to trigger the authorization bypass and gain takeover.

Generated by OpenCVE AI on September 20, 2026 at 06:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle Contracts security patch that rectifies the elevated‑privilege deficiency (CWE‑269).
  • Restrict inbound HTTP traffic to Oracle Contracts to trusted internal hosts or secure VPN links, thereby limiting the attack surface for potential high‑privileged traffic.
  • Enable comprehensive authentication and authorization logging; conduct periodic penetration testing to verify that privileged access controls are functioning as intended.

Generated by OpenCVE AI on September 20, 2026 at 06:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title High‑Privilege Authorization Bypass in Oracle Contracts

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title High‑Privileged HTTP Exploit Enables Oracle Contracts Takeover
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title High‑Privileged HTTP Exploit Enables Oracle Contracts Takeover
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle contracts
CPEs cpe:2.3:a:oracle:contracts:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contracts
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Contracts
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:22.729Z

Reserved: 2026-08-31T15:40:57.361Z

Link: CVE-2026-83481

cve-icon Vulnrichment

Updated: 2026-09-17T12:58:11.907Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:55.807

Modified: 2026-09-17T14:17:45.150

Link: CVE-2026-83481

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T01:30:18Z

Weaknesses
  • CWE-269

    Improper Privilege Management