Junglewise Threat Intelligence

CVE-2026-87164: Oracle Banking Branch privilege escalation via HTTP

CVE-2026-87164 · Severity: high · CVSS 8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Banking Branch is a banking software component used to manage branch operations and customer transactions. A vulnerability in its Reports module allows a low-privileged attacker with network access to escalate privileges and compromise the system if a user clicks a malicious link or performs an action. A successful attack could grant the attacker full control over the banking application, potentially exposing customer data and disrupting banking operations.

Technical details

This is a privilege escalation vulnerability in the Reports component of Oracle Banking Branch that requires low privileges and network access via HTTP. The attack is difficult to exploit and requires social engineering (user interaction via UI) to succeed. The vulnerability has a scope change, meaning exploitation can impact other Oracle Financial Services Applications beyond the Banking Branch itself. An attacker can achieve complete takeover (confidentiality, integrity, and availability compromise) of the affected system. Affected versions range from 14.5.0.0.0 through 14.9.0.0.0; patch status is not confirmed in the advisory.

Affected products

  • Oracle Banking Branch 14.5.0.0.0 to 14.9.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats