Executive brief
A vulnerability exists in Oracle Public Sector Financials, a suite used by government organizations to manage budgeting and accounting. An authorized user with low-level permissions could exploit this flaw to view, modify, or delete certain financial data they should not have access to. This could lead to unauthorized changes in financial records or the exposure of sensitive internal information.
Technical details
A vulnerability in the Internal Operations component of Oracle Public Sector Financials (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to read a subset of data and perform unauthorized updates, inserts, or deletions of certain accessible data. The vulnerability affects versions 12.2.3 through 12.2.15 and was addressed in the July 2026 Oracle Critical Patch Update.
Affected products
- Oracle Public Sector Financials 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory