Executive brief
Oracle Depot Repair is a component within Oracle E-Business Suite used for managing equipment repair operations. A network-accessible vulnerability allows a low-privileged user to gain complete control over the Depot Repair system, potentially compromising confidential repair records, operational data, and system integrity across the enterprise.
Technical details
A network-exploitable vulnerability in Oracle Depot Repair (component: Internal Operations) allows a low-privileged attacker with HTTP access to escalate privileges and achieve full system compromise. The vulnerability requires user authentication but no special interaction, and affects versions 12.2.10 through 12.2.15. Successful exploitation grants the attacker complete confidentiality, integrity, and availability compromise of the Depot Repair module, enabling data exfiltration, operational disruption, or further lateral movement within E-Business Suite. Oracle has issued a security advisory (CSPUSep2026) for this CVE; patch or workaround availability should be verified directly with Oracle support.
Affected products
- Oracle E-Business Suite Depot Repair 12.2.10-12.2.15
Timeline
- 2026-09-15: disclosed
- 2026-09-15: advisory: Oracle Security Alert CSPUSep2026