Junglewise Threat Intelligence

CVE-2026-87149: Oracle Contract Lifecycle Management for Public Sector unauthorized data access

CVE-2026-87149 · Severity: high · CVSS 7.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Contract Lifecycle Management for Public Sector is an application used to manage government contracts within Oracle E-Business Suite. A vulnerability allows an authenticated user with network access to read sensitive contract data and modify contract records without proper authorization, potentially exposing confidential procurement information.

Technical details

The vulnerability is an authorization flaw in the Award/PO component of Oracle Contract Lifecycle Management for Public Sector versions 12.2.8 through 12.2.15. It is easily exploitable by a low-privileged authenticated user with network access via HTTP, requiring no user interaction. An attacker can gain unauthorized read access to critical contract data and perform unauthorized update, insert, or delete operations on accessible contract records. The vulnerability has a CVSS 3.1 score of 7.1 with high confidentiality and low integrity impacts. Patches are expected from Oracle.

Affected products

  • Oracle E-Business Suite Contract Lifecycle Management for Public Sector 12.2.8 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats