Executive brief
Oracle E-Business Suite's Product Hub is a module that manages product and item catalog data critical to order processing and inventory management. A vulnerability allows a low-privileged user with network access to read sensitive product data without authorization, potentially exposing pricing, inventory, and supplier information across the entire catalog. The impact extends beyond Product Hub to other connected systems that rely on this data.
Technical details
This is an authorization bypass vulnerability in the Oracle Product Hub Item Catalog component affecting versions 12.2.3–12.2.15. The flaw is easily exploitable over HTTP by an authenticated low-privilege user (no admin rights required), with no complex preconditions. The vulnerability results in a scope change—meaning an attacker can access resources outside the Product Hub module itself. Successful exploitation allows unauthorized reading of critical data, though modification and availability are not impacted. Oracle released a patch in the September 2026 Critical Patch Update.
Affected products
- Oracle E-Business Suite 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched