Executive brief
A vulnerability exists in the Enterprise Command Center component of Oracle Project Costing, a tool used by businesses to manage and track project-related expenses. A high-privileged user could exploit this flaw over the network to gain full control of the Project Costing system. This could lead to the unauthorized modification of financial data, theft of sensitive project information, or a total disruption of project management operations.
Technical details
This vulnerability affects the Enterprise Command Center component within Oracle Project Costing (Oracle E-Business Suite) versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that can be triggered by a high-privileged attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle Project Costing product, impacting confidentiality, integrity, and availability. While the specific vulnerability class (e.g., injection, insecure deserialization) is not explicitly detailed in the advisory, the impact is rated as a full compromise of the component. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Project Costing (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory