Description
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Integrity and Confidentiality Compromise
Action: Immediate Patch
AI Analysis

Impact

A vulnerability exists in the Create Item Instance component of Oracle Installed Base within Oracle E-Business Suite. An attacker with low privileges and network access via HTTP can exploit this flaw to create, delete, or modify data that normally requires higher authority. The impact is the unauthorized alteration or deletion of critical data, and the potential to gain unauthorized read access to all data served by Oracle Installed Base. The weakness is a failure of proper access control and privilege management.

Affected Systems

Systems running Oracle Installed Base from versions 12.2.3 through 12.2.15 are affected. These include all installations of the Oracle E-Business Suite that contain the vulnerable Create Item Instance module.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates a high severity with substantial confidentiality and integrity impacts. The EPSS score of less than 1% suggests that, while the vulnerability is exploitable, the probability of it being used in the wild is currently low. The vulnerability is not listed in CISA's KEV catalog. An attacker can reach the vulnerable component over HTTP from the network, requiring only low privileges. If successfully exploited, the attacker can execute unauthorized data operations on the Oracle Installed Base.

Generated by OpenCVE AI on September 20, 2026 at 06:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest security update from Oracle for the Create Item Instance component
  • Restrict HTTP access to the Oracle Installed Base interface to trusted sources or a secure VPN
  • Review and enforce least‑privilege permissions on all users interacting with Create Item Instance
  • Monitor logs for unexpected data creation or deletion activity

Generated by OpenCVE AI on September 20, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Oracle Installed Base Create Item Instance Vulnerability Allows Unauthorized Data Modification

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Low‑Privilege HTTP Access in Oracle Installed Base
Weaknesses CWE-269
CWE-286
CWE-284

Wed, 16 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Low‑Privilege HTTP Access in Oracle Installed Base
Weaknesses CWE-269
CWE-286

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle installed Base
CPEs cpe:2.3:a:oracle:installed_base:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle installed Base
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Installed Base
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:15:19.261Z

Reserved: 2026-09-08T21:49:12.398Z

Link: CVE-2026-87152

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:02.660

Modified: 2026-09-18T19:17:10.763

Link: CVE-2026-87152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:00:08Z

Weaknesses