Junglewise Threat Intelligence

CVE-2026-47033: Oracle E-Business Suite compromise in Contracts Integration

CVE-2026-47033 · Severity: high · CVSS 8.5 · Published 2026-07-21

Technologies: Oracle Contracts Integration. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Oracle Contracts Integration component of the Oracle E-Business Suite, which is used by organizations to manage and integrate business contracts. A low-privileged attacker could exploit this flaw to take full control of the system, potentially leading to the theft of sensitive contract data or disruption of business operations. Because this component is integrated with other business systems, an attack could also spread to impact other parts of the enterprise software suite.

Technical details

This vulnerability affects the Internal Operations component of Oracle Contracts Integration within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a high-severity issue that allows a low-privileged attacker with network access via HTTP to compromise the application. While the attack complexity is rated as high, a successful exploit results in a scope change (S:C), meaning the attacker can impact components beyond the immediate security scope of Oracle Contracts Integration. The ultimate impact is a complete takeover of the affected product, compromising confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Contracts Integration (E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats