Executive brief
Oracle E-Business Suite Sales Online is a cloud-based sales management application used by enterprises to manage customer relationships and order processing. A vulnerability in the Internal Operations component allows a low-privileged user with network access to gain full administrative control of the Sales Online system, potentially exposing sensitive customer and order data, and disrupting sales operations.
Technical details
The vulnerability is a privilege escalation flaw in the Oracle E-Business Suite Sales Online product (Internal Operations component) affecting versions 12.2.3 through 12.2.15. It is exploitable over the network via HTTP by an attacker with low-level user privileges and requires no user interaction. Successful exploitation allows complete takeover of the Sales Online instance, with impact to confidentiality, integrity, and availability of the system. The vulnerability was published in September 2026 but is currently not known to be actively exploited in the wild.
Affected products
- Oracle E-Business Suite Sales Online 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed