Junglewise Threat Intelligence

CVE-2026-87265: Oracle E-Business Suite Purchasing unauthorized data access

CVE-2026-87265 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Purchasing, Oracle E-Business Suite Purchasing. Vendors: Oracle.

Executive brief

Oracle E-Business Suite's Purchasing module contains a vulnerability that allows a low-privileged attacker with network access to read, modify, or delete critical purchasing data. An attacker can exploit this via HTTP to gain unauthorized access to all purchasing information without requiring special user interaction, potentially exposing sensitive business operations and financial records.

Technical details

This is an authorization flaw in Oracle E-Business Suite Purchasing (versions 12.2.3–12.2.15) accessible via HTTP. The vulnerability requires low-privilege authentication but does not require user interaction or special configuration (AC:L). A successful exploit grants an attacker confidentiality and integrity access to critical purchasing data—including unauthorized creation, deletion, and modification of records. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) reflects network attack vector, low complexity, and high impact to confidentiality and integrity. Patch availability and the precise nature of the authorization flaw are not detailed in the advisory.

Affected products

  • Oracle E-Business Suite Purchasing 12.2.3–12.2.15

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory

References

Related threats