Executive brief
Oracle Product Hub, a core component of Oracle E-Business Suite used for managing product data across enterprise systems, contains a privilege escalation vulnerability in its Outbound Data module. A low-privileged attacker with network access can exploit this flaw to gain complete control over the Product Hub system, potentially compromising sensitive product data, business processes, and system integrity.
Technical details
This is a privilege escalation vulnerability in the Outbound Data component of Oracle Product Hub (E-Business Suite). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP, requiring no user interaction. Successful exploitation allows an attacker to achieve complete system compromise of Oracle Product Hub, affecting confidentiality, integrity, and availability. The vulnerability impacts versions 12.2.3 through 12.2.15, and no active in-the-wild exploitation has been reported as of the advisory publication date.
Affected products
- Oracle E-Business Suite Product Hub 12.2.3-12.2.15
Timeline
- 2026-08-18: disclosed