Executive brief
A vulnerability exists in the Core Receiving component of Oracle Inventory Management, a tool used by businesses to track stock and supply chain operations. A user with low-level access to the system can exploit this flaw over the network to view, modify, or delete sensitive inventory data. This could lead to significant disruptions in supply chain accuracy, unauthorized changes to stock records, and the exposure of proprietary business information.
Technical details
A vulnerability in the Core Receiving component of Oracle Inventory Management (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation grants the attacker the ability to create, delete, or modify all accessible data within the Inventory Management module, as well as read-only access to critical data. The vulnerability affects versions 12.2.3 through 12.2.15. It is tracked as part of the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle Corporation Oracle Inventory Management (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.