Junglewise Threat Intelligence

CVE-2026-87151: Oracle Bills of Material unauthorized data access in Setup Workbench

CVE-2026-87151 · Severity: high · CVSS 7.7 · Published 2026-09-15

Technologies: Oracle E-Business Suite Bills of Material. Vendors: Oracle.

Executive brief

Oracle Bills of Material (BOM) is a component of Oracle E-Business Suite used to manage product structure and manufacturing data. An authenticated attacker with low privilege network access can exploit this vulnerability in the Setup Workbench module to read critical or sensitive BOM data, potentially exposing confidential manufacturing information or business logic across the E-Business Suite environment.

Technical details

This is an authorization/access control vulnerability in the Oracle Bills of Material Setup Workbench component affecting E-Business Suite versions 12.2.3–12.2.15. The vulnerability is easily exploitable and requires low privilege authentication and network access via HTTP; no user interaction is needed. An authenticated attacker can gain unauthorized read access to critical Bills of Material data. The vulnerability has scope change implications, potentially affecting additional Oracle E-Business Suite products beyond Bills of Material. No patch or workaround details are publicly available in the provided advisory.

Affected products

  • Oracle E-Business Suite Bills of Material 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory

References

Related threats