CVE-2026-87162

Oracle · Oracle Contract Lifecycle Management for Public Sector

A vulnerability in the Oracle Contract Lifecycle Management for Public Sector component of Oracle E-Business Suite allows low-privileged attackers to achieve full system takeover.

Executive summary

A critical vulnerability in Oracle Contract Lifecycle Management for Public Sector allows authenticated attackers to gain complete control over the affected application.

Vulnerability

This flaw exists within the Award/PO component and permits an attacker with low-level privileges to perform unauthorized actions via HTTP. The vulnerability is easily exploitable and leads to a full system takeover of the affected product.

Business impact

The potential for a full system takeover presents a severe risk to organizational operations, as it grants attackers the ability to manipulate sensitive contract data, alter procurement records, and potentially pivot within the E-Business Suite environment. Given the high CVSS score of 8.8, this vulnerability poses a significant threat to the confidentiality, integrity, and availability of critical financial and public sector infrastructure.

Remediation

Immediate Action: Organizations should consult the official Oracle Security Alert page at https://www.oracle.com/security-alerts/cspusep2026.html and apply the necessary security patches or cumulative updates as soon as they are released.

Proactive Monitoring: Security teams should review application access logs for unusual administrative activity or unexpected HTTP requests targeting the Award/PO component.

Compensating Controls: Implement strict network segmentation and utilize Web Application Firewalls to filter malicious traffic patterns aimed at the affected E-Business Suite modules.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high severity and the potential for a complete system compromise, immediate attention is required to secure the Oracle E-Business Suite environment. Administrators must prioritize the identification of affected systems and prepare to apply vendor-supplied updates immediately upon their availability to neutralize this risk.

More Oracle CVEs all →

History

  1. Collected by CVE Brief via github
  2. Held for re-check analysis graded thin
  3. Analyst report written

Sources