Junglewise Threat Intelligence

CVE-2026-87150: Oracle Bills of Material privilege escalation in Setup Workbench

CVE-2026-87150 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle E-Business Suite Bills of Material. Vendors: Oracle.

Executive brief

Oracle Bills of Material is a component of Oracle E-Business Suite used to manage product structures and manufacturing hierarchies. A low-privileged user with network access can exploit an easily exploitable vulnerability in the Setup Workbench to gain full control of the Bills of Material system, potentially compromising manufacturing data integrity and availability.

Technical details

An easily exploitable vulnerability exists in the Setup Workbench component of Oracle Bills of Material (versions 12.2.3–12.2.15) that allows a low-privileged attacker with network access via HTTP to achieve complete compromise. The vulnerability requires low privileges and no user interaction, and is network-reachable. Successful exploitation results in complete takeover of the Bills of Material system, affecting confidentiality, integrity, and availability. A patch is available via Oracle's standard critical patch update process.

Affected products

  • Oracle E-Business Suite Bills of Material 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats