Junglewise Threat Intelligence

CVE-2026-62473: Oracle Installed Base unauthorized data access in Create Item Instance

CVE-2026-62473 · Severity: high · CVSS 8.3 · Published 2026-07-21

Technologies: Oracle Installed Base. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in Oracle Installed Base, a component of the Oracle E-Business Suite used for tracking product lifecycles and customer assets. An attacker with basic user credentials can exploit this flaw over the network to gain full access to sensitive asset data, allowing them to view, modify, or delete critical business records. This could lead to significant data integrity issues, unauthorized information disclosure, and partial disruption of the service.

Technical details

This vulnerability affects the 'Create Item Instance' component of Oracle Installed Base within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and is reachable via HTTP over the network. An attacker can achieve high impacts to confidentiality and integrity, potentially gaining full unauthorized access to or modification of all data within the Installed Base module. Additionally, the exploit can result in a partial denial of service. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Oracle Installed Base 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: NVD publication date
  • 2026-07-21: disclosed: Oracle security alert published

References

Related threats