Description
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification
Action: Patch ASAP
AI Analysis

Impact

The vulnerability allows a low‑privileged attacker with HTTP access to create, delete, or modify critical data in Oracle Product Hub, leading to unauthorized data tampering and loss of confidentiality and integrity.

Affected Systems

Oracle Product Hub, a component of Oracle E‑Business Suite, is affected for all supported releases from version 12.2.3 up to 12.2.15 inclusive.

Risk and Exploitability

With a CVSS v3.1 base score of 8.1 and an EPSS probability under 1 %, the issue presents a high impact to confidentiality and integrity but low likelihood of exploitation; attackers need only network reachability to the HTTP endpoint and low privileges to successfully compromise the system, so organizations should treat it as a high‑risk vulnerability.

Generated by OpenCVE AI on September 18, 2026 at 17:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle Product Hub security patch released for versions 12.2.3 through 12.2.15 that addresses this issue
  • Restrict HTTP access to Oracle Product Hub to authorized IP ranges or implement VPN access to limit network exposure
  • Configure strict access controls and role‑based permissions within Oracle Product Hub to ensure users have only the minimum privileges necessary for their tasks

Generated by OpenCVE AI on September 18, 2026 at 17:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege HTTP Access in Oracle Product Hub

Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege HTTP Access in Oracle Product Hub
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle product Hub
CPEs cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Hub
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Product Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:14:36.144Z

Reserved: 2026-09-08T21:49:12.398Z

Link: CVE-2026-87153

cve-icon Vulnrichment

Updated: 2026-09-18T18:14:30.630Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:02.770

Modified: 2026-09-22T19:03:53.577

Link: CVE-2026-87153

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:15:11Z

Weaknesses