Executive brief
Oracle Product Hub is a core component of Oracle E-Business Suite used to manage product data and operations. A privilege escalation vulnerability allows high-privileged attackers to gain complete control of the Product Hub system via network access, compromising data confidentiality, integrity, and system availability.
Technical details
This vulnerability in Oracle E-Business Suite's Product Hub (Internal Operations component) is exploitable by high-privileged attackers with network access over HTTP. The vulnerability requires high privileges and allows network-based exploitation without user interaction. Successful exploitation results in full compromise of the Product Hub system, affecting confidentiality, integrity, and availability. Affected versions are 12.2.3 through 12.2.15; patches are available from Oracle's security alerts.
Affected products
- Oracle E-Business Suite Product Hub 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed
- other: CVE-2026-83440 assigned