Executive brief
A vulnerability exists in the Production component of Oracle's Complex Maintenance, Repair and Overhaul (CMRO) software, which is used by organizations to manage heavy equipment maintenance and engineering. A low-privileged user could exploit this flaw to take full control of the system, potentially leading to the theft of sensitive maintenance data or disruption of critical repair operations. Because this component is integrated with the broader Oracle E-Business Suite, an attack could also impact other connected business systems.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the Production component of Oracle Complex Maintenance, Repair and Overhaul. It is exploitable by a low-privileged attacker with network access via HTTP, though Oracle notes the exploit complexity is high. A successful exploit results in a 'scope change' (SSVC technical impact: total), meaning the attacker can move beyond the CMRO component to impact other parts of the Oracle E-Business Suite environment. The vulnerability allows for a complete takeover of the affected product, impacting confidentiality, integrity, and availability. Affected versions include 12.2.3 through 12.2.15.
Affected products
- Oracle Complex Maintenance, Repair and Overhaul 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory