CVE-2026-47031
Oracle · Oracle Bills of Material
A vulnerability in the Bill Issues component of Oracle Bills of Material allows a low privileged attacker to compromise the application via network access.
Executive summary
An attacker with low privileges can exploit a vulnerability in the Oracle Bills of Material component of Oracle E-Business Suite to gain full control of the application.
Vulnerability
This vulnerability resides in the Bill Issues component and allows a low-privileged attacker with network access via HTTP to perform a successful takeover of the software.
Business impact
The CVSS score of 8.8 highlights the critical nature of this vulnerability within the Oracle E-Business Suite ecosystem. A successful compromise could result in the unauthorized modification of manufacturing data, production disruption, and potential exposure of sensitive supply chain information.
Remediation
Immediate Action: Apply the security updates provided in the July 2026 Oracle Critical Patch Update as soon as they are available.
Proactive Monitoring: Monitor HTTP traffic and application logs for unusual queries or administrative commands originating from low-privileged accounts.
Compensating Controls: Utilize network segmentation to restrict access to the Oracle E-Business Suite to authorized personnel only, reducing the likelihood of an attacker reaching the vulnerable component.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity and the potential impact on business-critical supply chain data, immediate patching is required. Organizations should ensure that all instances of Oracle Bills of Material within the specified version range are updated as part of the next maintenance cycle.