Junglewise Threat Intelligence

CVE-2026-87162: Oracle Contract Lifecycle Management for Public Sector privilege escalation in Award/PO

CVE-2026-87162 · Severity: high · CVSS 8.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Contract Lifecycle Management for Public Sector is a module within Oracle E-Business Suite used to manage contracts and purchase orders for government agencies. A network-accessible vulnerability allows a low-privileged user to gain complete control of the system, potentially exposing sensitive government contract data and enabling unauthorized modifications to purchase orders and awards.

Technical details

A privilege escalation vulnerability exists in the Award/PO component of Oracle Contract Lifecycle Management for Public Sector (E-Business Suite). The vulnerability is easily exploitable and requires network access via HTTP and low-level user privileges; no user interaction is required. Successful exploitation allows an attacker to achieve complete compromise of the affected system, including unauthorized access to confidential contract information, modification of purchase orders and awards, and denial of service. Affected versions are 12.2.13 through 12.2.15; patches are expected from Oracle.

Affected products

  • Oracle E-Business Suite Contract Lifecycle Management for Public Sector 12.2.13-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats