Junglewise Threat Intelligence

CVE-2026-87153: Oracle E-Business Suite Product Hub unauthorized data access

CVE-2026-87153 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle E-Business Suite Product Hub, Oracle Product Hub. Vendors: Oracle.

Executive brief

Oracle E-Business Suite's Product Hub component is vulnerable to unauthorized data access and modification by network-based attackers with low-level user privileges. This vulnerability allows attackers to read, create, delete, or modify critical business data stored in the Product Hub. Organizations using affected versions (12.2.3–12.2.15) should prioritize patching to prevent data breaches and integrity compromise.

Technical details

This vulnerability in Oracle E-Business Suite's Product Hub (Internal Operations component) allows low-privileged, authenticated network attackers to bypass authorization controls via HTTP. The attack requires valid user credentials but no user interaction. Successful exploitation grants attackers unauthorized read, creation, deletion, and modification access to critical data and all accessible Product Hub records. The vulnerability affects versions 12.2.3 through 12.2.15; patch availability and specific remediation details should be confirmed via Oracle's official security bulletin.

Affected products

  • Oracle E-Business Suite Product Hub 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats