Executive brief
A vulnerability exists in the Internal Operations component of Oracle E-Business Suite's manufacturing module. This flaw allows a user with low-level access to take full control over the manufacturing management system. Such an exploit could lead to the theft of sensitive production data, disruption of manufacturing operations, or unauthorized changes to industrial processes.
Technical details
This vulnerability is classified under improper privilege management and authentication bypass (CWE-269, CWE-287, CWE-306) within the Internal Operations component of Oracle Outsourced Mfg for Discrete Industries. It is easily exploitable via HTTP by a low-privileged attacker with network access. Successful exploitation grants the attacker full control over the affected component, impacting confidentiality, integrity, and availability. The issue affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle E-Business Suite Outsourced Mfg for Discrete Industries 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date