CVE-2026-87162
Oracle · Oracle Contract Lifecycle Management for Public Sector
A vulnerability in the Oracle Contract Lifecycle Management for Public Sector component of Oracle E-Business Suite allows low-privileged attackers to achieve full system takeover.
Executive summary
A critical vulnerability in Oracle Contract Lifecycle Management for Public Sector allows authenticated attackers to gain complete control over the affected application.
Vulnerability
This flaw exists within the Award/PO component and permits an attacker with low-level privileges to perform unauthorized actions via HTTP. The vulnerability is easily exploitable and leads to a full system takeover of the affected product.
Business impact
The potential for a full system takeover presents a severe risk to organizational operations, as it grants attackers the ability to manipulate sensitive contract data, alter procurement records, and potentially pivot within the E-Business Suite environment. Given the high CVSS score of 8.8, this vulnerability poses a significant threat to the confidentiality, integrity, and availability of critical financial and public sector infrastructure.
Remediation
Immediate Action: Organizations should consult the official Oracle Security Alert page at https://www.oracle.com/security-alerts/cspusep2026.html and apply the necessary security patches or cumulative updates as soon as they are released.
Proactive Monitoring: Security teams should review application access logs for unusual administrative activity or unexpected HTTP requests targeting the Award/PO component.
Compensating Controls: Implement strict network segmentation and utilize Web Application Firewalls to filter malicious traffic patterns aimed at the affected E-Business Suite modules.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high severity and the potential for a complete system compromise, immediate attention is required to secure the Oracle E-Business Suite environment. Administrators must prioritize the identification of affected systems and prepare to apply vendor-supplied updates immediately upon their availability to neutralize this risk.
More Oracle CVEs all →
History
- Collected by CVE Brief via github
- Held for re-check analysis graded thin
- Analyst report written
Sources
- Oracle Advisory Vendor advisory