Junglewise Threat Intelligence

CVE-2026-87169: Oracle Contract Lifecycle Management for Public Sector CSRF in Wage Determination Online

CVE-2026-87169 · Severity: medium · CVSS 6.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Contract Lifecycle Management for Public Sector is a module of Oracle E-Business Suite used to manage contracts for government organizations. A vulnerability in the Wage Determination Online component allows an unauthenticated attacker to trick authorized users into performing unauthorized actions, potentially reading or modifying sensitive contract and wage determination data.

Technical details

This is a cross-site request forgery (CSRF) vulnerability in the Wage Determination Online component of Oracle Contract Lifecycle Management for Public Sector. The vulnerability is easily exploitable via HTTP without authentication, but requires user interaction—the attacker must trick a legitimate user into clicking a malicious link or visiting a crafted page while authenticated. Successful exploitation allows an attacker to read a subset of accessible data and perform unauthorized updates, insertions, or deletions to contract and wage determination records. The vulnerability affects versions 12.2.3 through 12.2.15 and has a scope change impact, meaning it may affect other Oracle E-Business Suite products. Patches are likely available from Oracle through their regular security update channels.

Affected products

  • Oracle Contract Lifecycle Management for Public Sector 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats