Executive brief
A vulnerability exists in the Oracle E-Business Suite's attachment upload feature, which is used by businesses to manage enterprise resources and documentation. An attacker with basic user access could potentially view, modify, or delete certain data within the system. This attack requires a legitimate user to interact with a malicious link or file, which could lead to unauthorized changes to business records or the exposure of sensitive internal information.
Technical details
This vulnerability affects the Oracle Applications Framework (OAF) within Oracle E-Business Suite, specifically the 'Upload Attachments' component. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the framework. The attack requires human interaction (User Interaction: Required) from a victim. Successful exploitation enables the attacker to perform unauthorized updates, insertions, or deletions of a subset of OAF data, as well as unauthorized read access to specific data. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Oracle Applications Framework 12.2.8-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
- 2026-07-21: disclosed: NVD published the CVE record.