Description
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification, deletion, or creation of critical data in Oracle Purchasing, and unauthorized access to all application data
Action: Immediate Patch
AI Analysis

Impact

Oracle Purchasing is vulnerable to an access-control failure that permits an attacker with low privileges and network connectivity over HTTP to create, modify, delete, or otherwise alter critical data. The flaw also allows unrestricted access to all data reachable by the application, compromising both confidentiality and integrity of Oracle Purchasing data.

Affected Systems

Oracle Purchasing within Oracle E-Business Suite, supporting versions 12.2.3 through 12.2.15. The issue does not affect other Oracle products and is limited to this specific application component.

Risk and Exploitability

The flaw carries a CVSS 3.1 base score of 8.1, indicating high severity; the EPSS score of <1% suggests limited automated exploitation but still plausible manual attacks. It is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability by sending crafted HTTP requests to a low-privileged account. Based on the description, it is inferred that OS privileges are not required to exploit this vulnerability, and no complex configuration is necessary.

Generated by OpenCVE AI on September 21, 2026 at 03:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle's latest security patch for Oracle Purchasing to address the access control issue.
  • Limit network access to the Purchasing service to trusted hosts or networks through firewall rules or VPN restrictions.
  • Enforce stricter role-based access controls in Oracle Purchasing so low-privileged accounts cannot perform data creation, modification, or deletion operations.
  • Implement comprehensive logging and monitoring of data modification activities and configure alerts for unauthorized changes.

Generated by OpenCVE AI on September 21, 2026 at 03:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Oracle Purchasing Access Control Flaw Enables Low-Privilege Data Modification and Full Data Access

Mon, 21 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Access Control Failure in Oracle Purchasing Allows Low-Privilege Data Manipulation and Unauthorized Access
Weaknesses CWE-285

Mon, 21 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Access Control Failure in Oracle Purchasing Allows Low-Privilege Data Manipulation and Unauthorized Access
Weaknesses CWE-285

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Modification, Deletion, and Creation of Data via Access Control Failure in Oracle Purchasing
Weaknesses CWE-284

Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Modification, Deletion, and Creation of Data via Access Control Failure in Oracle Purchasing
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle purchasing
CPEs cpe:2.3:a:oracle:purchasing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle purchasing
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Purchasing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-20T23:53:13.530Z

Reserved: 2026-09-08T21:49:12.400Z

Link: CVE-2026-87166

cve-icon Vulnrichment

Updated: 2026-09-20T23:45:35.817Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:04.280

Modified: 2026-09-22T19:02:21.400

Link: CVE-2026-87166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:00:13Z

Weaknesses