CVE-2026-87150
Oracle · Oracle Bills of Material
A vulnerability in the Oracle Bills of Material Setup Workbench allows low privileged, authenticated attackers to achieve full system takeover via HTTP.
Executive summary
A high-severity vulnerability in the Oracle Bills of Material component of Oracle E-Business Suite allows low-privileged attackers to gain complete control over the affected system.
Vulnerability
This is a high-severity flaw within the Setup Workbench component that allows a low-privileged, authenticated user to perform a full system takeover. The attack vector is network-based via HTTP and requires no user interaction to execute.
Business impact
Successful exploitation of this vulnerability results in a complete takeover of the Oracle Bills of Material component, leading to a total loss of confidentiality, integrity, and availability. Given the CVSS score of 8.8, this represents a significant risk to organizational operations, as attackers could modify sensitive production data, intercept proprietary manufacturing information, or disrupt critical business workflows.
Remediation
Immediate Action: Organizations should review the official Oracle Security Alert for September 2026 and apply the necessary patches as soon as they are made available by the vendor.
Proactive Monitoring: Security teams should monitor network traffic and application logs for unusual HTTP requests directed at the Setup Workbench, particularly those originating from accounts with low-level privileges.
Compensating Controls: Deploy Web Application Firewall rules to inspect and filter HTTP requests targeting the Setup Workbench component, specifically looking for anomalous patterns that deviate from standard user behavior.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the potential for total system takeover, this vulnerability poses a severe threat to the integrity of the Oracle E-Business Suite environment. Administrators must prioritize the installation of vendor-supplied patches immediately upon release to mitigate the risk of unauthorized access and system compromise.
More Oracle CVEs all →
History
- Collected by CVE Brief via github
- Held for re-check analysis graded thin
- Analyst report written
Sources
- Oracle Advisory Vendor advisory