Description
Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Branch. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Branch, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Banking Branch. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote System Compromise
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in the Reports component of Oracle Banking Branch (versions 14.5.0.0.0 through 14.9.0.0.0) allows a low‑privileged attacker with network access over HTTP to trigger an exploit that requires human interaction from a user other than the attacker; successful exploitation results in full takeover of the application, compromising confidentiality, integrity, and availability.

Affected Systems

Oracle Banking Branch of Oracle Financial Services Applications is affected with the version range 14.5.0.0.0–14.9.0.0.0, as identified by the vendor.

Risk and Exploitability

The CVSS 8.0 score indicates severe impact, while the EPSS score of less than 1% shows a very low but still present exploitation probability; this vulnerability is not listed in CISA KEV. The attack requires a user‑initiated action, lowering the likelihood of automated attacks, but it still poses a significant risk, particularly if social engineering is used, and the mentioned scope change could allow impact on additional products.

Generated by OpenCVE AI on September 17, 2026 at 23:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Banking Branch patch that addresses the Reports component vulnerability (upgrade to a release higher than 14.9.0.0.0).
  • If a patch is not yet available, isolate the Banking Branch system from external HTTP traffic and limit access to trusted internal hosts only.
  • Enable multi‑factor authentication for all user sessions and monitor for suspicious account activity.
  • Restrict or disable unused reporting functions that may expose the vulnerable code path.

Generated by OpenCVE AI on September 17, 2026 at 23:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Leads to Oracle Banking Branch Takeover
Weaknesses CWE-285
CWE-287

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Leads to Oracle Banking Branch Takeover
Weaknesses CWE-285
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Branch. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Branch, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Banking Branch. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle banking Branch
CPEs cpe:2.3:a:oracle:banking_branch:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle banking Branch
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Banking Branch
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:21.107Z

Reserved: 2026-09-08T21:49:12.399Z

Link: CVE-2026-87164

cve-icon Vulnrichment

Updated: 2026-09-17T12:57:35.600Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:04.060

Modified: 2026-09-17T14:17:47.753

Link: CVE-2026-87164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management