Description
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Enterprise Command Center). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Order Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data and database access
Action: Patch urgently
AI Analysis

Impact

A flaw exists in Oracle Order Management, allowing an attacker with low privileges who can reach the system over HTTP to obtain unauthorized access to critical data or all Order Management information. Successful exploitation can lead to reading confidential information and modifying, inserting, or deleting data, which results in high confidentiality loss and some integrity compromise. The weakness manifests as improper access control allowing unauthorized manipulation of data.

Affected Systems

The affected product is Oracle Order Management, part of Oracle E-Business Suite, specifically version v16. Organizations using this version are directly impacted.

Risk and Exploitability

The CVSS v3.1 score of 7.1 indicates a moderate to high severity, with potential for significant confidentiality impact. The EPSS score is below 1%, suggesting a low current probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the network over HTTP, targeting users with low level access privileges. Successful exploitation requires no user interaction, and the impact is confined to the scope of the compromised application.

Generated by OpenCVE AI on September 20, 2026 at 06:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Order Management v16 to fix the access control flaw
  • Restrict inbound HTTP traffic to Order Management to trusted IP ranges or VPN access
  • Enforce least privilege and review role assignments to ensure users have only required access
  • Monitor application logs for anomalous read or write activity targeting Order Management data

Generated by OpenCVE AI on September 20, 2026 at 06:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthorized access to Oracle Order Management via HTTP

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Allows Unauthorized Data Access in Oracle Order Management v16
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Allows Unauthorized Data Access in Oracle Order Management v16
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Enterprise Command Center). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Order Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle order Management
CPEs cpe:2.3:a:oracle:order_management:v16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle order Management
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Order Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:12:34.863Z

Reserved: 2026-09-08T21:49:12.399Z

Link: CVE-2026-87158

cve-icon Vulnrichment

Updated: 2026-09-18T18:12:29.542Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:03.327

Modified: 2026-09-18T18:17:20.593

Link: CVE-2026-87158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:45:17Z

Weaknesses