Junglewise Threat Intelligence

CVE-2026-87127: Oracle Purchasing unauthorized data access in E-Business Suite

CVE-2026-87127 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle Purchasing, Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle Purchasing is a critical component of Oracle's E-Business Suite, used for enterprise procurement and invoice management. A vulnerability allows low-privilege users with network access to view sensitive purchasing and invoice data without authorization, potentially exposing confidential procurement information and supplier details to unauthorized users.

Technical details

This is an unauthorized access vulnerability (CWE-639: Authorization Bypass Through User-Controlled Key) in the Oracle Purchasing product component G-Invoicing within Oracle E-Business Suite. The vulnerability is easily exploitable via HTTP network access and requires only low privileges and no user interaction to trigger. An attacker can achieve unauthorized read access to critical Purchasing data; the scope is changed meaning impacts extend to other E-Business Suite components. Affected versions are 12.2.10 through 12.2.15. A patch is expected from Oracle during their standard security update cycle.

Affected products

  • Oracle E-Business Suite 12.2.10-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats