Executive brief
Oracle Application Object Library is a core component of Oracle E-Business Suite that handles file attachments and document management. This vulnerability allows a low-privilege user to upload files and gain complete control of the application, potentially exposing confidential business data, modifying financial records or transactions, and disrupting critical business operations.
Technical details
This is a file upload vulnerability in the Attachments / File Upload component of Oracle Application Object Library that allows privilege escalation. It requires network access via HTTP and a valid (low-privilege) user account, but no user interaction. An authenticated attacker can exploit this to achieve arbitrary code execution or administrative takeover of the affected application, resulting in full compromise of confidentiality, integrity, and availability. The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15; Oracle has released patches as part of their September 2026 security update.
Affected products
- Oracle E-Business Suite Application Object Library 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed