CVE-2026-87150

Oracle · Oracle Bills of Material

A vulnerability in the Oracle Bills of Material Setup Workbench allows low privileged, authenticated attackers to achieve full system takeover via HTTP.

Executive summary

A high-severity vulnerability in the Oracle Bills of Material component of Oracle E-Business Suite allows low-privileged attackers to gain complete control over the affected system.

Vulnerability

This is a high-severity flaw within the Setup Workbench component that allows a low-privileged, authenticated user to perform a full system takeover. The attack vector is network-based via HTTP and requires no user interaction to execute.

Business impact

Successful exploitation of this vulnerability results in a complete takeover of the Oracle Bills of Material component, leading to a total loss of confidentiality, integrity, and availability. Given the CVSS score of 8.8, this represents a significant risk to organizational operations, as attackers could modify sensitive production data, intercept proprietary manufacturing information, or disrupt critical business workflows.

Remediation

Immediate Action: Organizations should review the official Oracle Security Alert for September 2026 and apply the necessary patches as soon as they are made available by the vendor.

Proactive Monitoring: Security teams should monitor network traffic and application logs for unusual HTTP requests directed at the Setup Workbench, particularly those originating from accounts with low-level privileges.

Compensating Controls: Deploy Web Application Firewall rules to inspect and filter HTTP requests targeting the Setup Workbench component, specifically looking for anomalous patterns that deviate from standard user behavior.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score and the potential for total system takeover, this vulnerability poses a severe threat to the integrity of the Oracle E-Business Suite environment. Administrators must prioritize the installation of vendor-supplied patches immediately upon release to mitigate the risk of unauthorized access and system compromise.

More Oracle CVEs all →

History

  1. Collected by CVE Brief via github
  2. Held for re-check analysis graded thin
  3. Analyst report written

Sources