Junglewise Threat Intelligence

CVE-2026-47019: Oracle Product Hub unauthorized data access in Item Catalog

CVE-2026-47019 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Product Hub. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Product Hub, a component of the Oracle E-Business Suite used for managing product data and item catalogs. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the unauthorized viewing, modification, or deletion of critical product information, potentially disrupting supply chain operations and compromising proprietary data.

Technical details

This vulnerability affects the Item Catalog component of Oracle Product Hub within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can leverage this vulnerability to achieve unauthorized creation, deletion, or modification of all data accessible to the Product Hub, as well as complete unauthorized read access to that data. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Product Hub (Item Catalog) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-47019 by Oracle
  • 2026-07-21: advisory: Oracle Critical Patch Update (CPU) released

References

Related threats