Executive brief
A vulnerability exists in the Cost Maintenance component of Oracle Cost Management, a tool used by businesses to manage and track manufacturing and supply chain costs. A low-privileged user could exploit this flaw over the network to gain full control of the Cost Management system. If successful, this could lead to the unauthorized modification of financial data, theft of sensitive cost information, or a total disruption of cost accounting operations.
Technical details
This vulnerability affects the Cost Maintenance component of Oracle Cost Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a high-severity issue that allows a low-privileged attacker with network access via HTTP to compromise the system. While the attack complexity is rated as high, a successful exploit results in a complete loss of confidentiality, integrity, and availability (takeover) of the affected component. The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle Cost Management (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD