Description
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. While the vulnerability is in Oracle Product Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Immediately
AI Analysis

Impact

The Oracle Product Hub within Oracle E‑Business Suite allows a low‑privileged attacker who can reach the hub over HTTP to read critical data or gain full access to all Oracle Product Hub data. The CVSS 3.1 Base Score of 7.7 reflects a high confidentiality impact with no impact on integrity or availability. The vulnerability arises in the Item Catalog component and permits unauthorized data access when the attacker does not possess proper authentication or authorization.

Affected Systems

Oracle Product Hub, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. The vulnerability originates in this product but the scope change in the CVE description indicates that successful exploitation could also impact additional products or systems that interact with the Product Hub.

Risk and Exploitability

The vulnerability is network‑based and requires only HTTP access over port 80/443, as explicitly stated in the CVE description. The attacker can be any compromised user with low privileges who has network connectivity to the host. Authentication is not required, so the attacker can read critical data or gain complete access to the Product Hub. The likely attack vector is through HTTP requests to the Item Catalog endpoint; this is inferred from the description. The CVSS base score of 7.7 indicates high risk to confidentiality, while the EPSS score of < 1% shows a low overall probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and the scope change noted in the description suggests that successful exploitation could also impact additional products that interact with the Product Hub.

Generated by OpenCVE AI on September 20, 2026 at 07:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Product Hub security patch or upgrade to a non‑vulnerable version.
  • Restrict external network access to the Oracle Product Hub to trusted IP ranges or application and system logs for anomalous read attempts or unusual access patterns to the Item Catalog endpoint.
  • Enable detailed logging and monitoring for requests to the Item Catalog endpoint to detect unauthorized data access attempts.

Generated by OpenCVE AI on September 20, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Item Catalog Access Control Bypass in Oracle Product Hub Allows Unauthorized Data Access
Weaknesses CWE-284

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Allows Unauthorized Data Exposure in Oracle Product Hub
Weaknesses CWE-284

Thu, 17 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Allows Unauthorized Data Exposure in Oracle Product Hub
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. While the vulnerability is in Oracle Product Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle product Hub
CPEs cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Hub
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Product Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T14:17:06.744Z

Reserved: 2026-08-31T15:40:57.362Z

Link: CVE-2026-83486

cve-icon Vulnrichment

Updated: 2026-09-22T14:16:59.038Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:56.370

Modified: 2026-09-22T19:06:01.267

Link: CVE-2026-83486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:30:17Z

Weaknesses