CVE-2026-87163
8.8Oracle · Oracle Purchasing
A high severity vulnerability in Oracle Purchasing allows a low privileged attacker to achieve a full system takeover via HTTP network access.
Executive summary
Oracle Purchasing is susceptible to a critical compromise vulnerability that permits low privileged attackers to seize control of the application.
Vulnerability
This vulnerability, residing within the Oracle Purchasing component of Oracle E-Business Suite, allows an attacker with low privileges to execute a takeover of the application via a network-based HTTP request. The flaw is easily exploitable and does not require user interaction.
Business impact
The potential for a complete takeover of Oracle Purchasing poses a severe risk to organizational operations, as this system often manages critical procurement and financial supply chain data. Given the CVSS score of 8.8, successful exploitation could lead to unauthorized data exfiltration, modification of procurement records, and significant operational disruption, resulting in substantial financial and reputational damage.
Remediation
Immediate Action: Review the official Oracle security advisory at the link provided in the references section and apply the relevant patch or update as soon as it becomes available.
Proactive Monitoring: Monitor network traffic for unusual HTTP patterns directed at Oracle E-Business Suite instances and audit user access logs for suspicious activity by low privileged accounts.
Compensating Controls: Deploy Web Application Firewall rules to inspect and filter traffic for malicious payloads targeting Oracle Purchasing endpoints until a vendor-supplied patch is applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a high risk to the availability and integrity of the Oracle E-Business Suite environment. Administrators should prioritize the identification of affected systems and prepare for an emergency patch deployment once the vendor releases the necessary updates. Failure to remediate this flaw leaves the procurement infrastructure exposed to unauthorized administrative takeover.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Oracle Advisory Vendor advisory