Executive brief
Oracle Engineering is a critical module within Oracle E-Business Suite used for managing engineering projects and product lifecycle data. A flaw in the Internal Operations component allows a low-privilege user with network access to modify or delete sensitive engineering data and access confidential project information, potentially impacting downstream business processes and data integrity across multiple connected systems.
Technical details
This is a privilege escalation vulnerability in Oracle Engineering's Internal Operations component, accessible via HTTP. The vulnerability requires low-level privileges and network access but is difficult to exploit (high attack complexity). An authenticated attacker can bypass access controls to perform unauthorized CRUD operations on critical data, with scope change indicating potential impact on other Oracle E-Business Suite modules. The vulnerability affects versions 12.2.3 through 12.2.15, and patches are expected from Oracle's September 2026 security release.
Affected products
- Oracle E-Business Suite Engineering 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed