Junglewise Threat Intelligence

CVE-2026-47028: Oracle E-Business Suite data compromise in Document Management and Collaboration

CVE-2026-47028 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle E-Business Suite Document Management and Collaboration. Vendors: Oracle.

Executive brief

A vulnerability exists in the Attachments component of Oracle E-Business Suite's Document Management and Collaboration tool, which is used by organizations to manage and share corporate documents. An attacker with basic user credentials can exploit this flaw over the network to gain full access to sensitive files. This could lead to the unauthorized viewing, modification, or deletion of critical business data, potentially disrupting operations and compromising proprietary information.

Technical details

This vulnerability affects the Attachments component of Oracle Document Management and Collaboration within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an improper access control or similar flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Exploitation does not require user interaction and can result in the unauthorized creation, deletion, or modification of all accessible data, as well as complete read access to critical information. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity, though availability is not directly affected. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle E-Business Suite (Document Management and Collaboration) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats