CVE-2026-87165
Oracle · Contract Lifecycle Management for Public Sector
A vulnerability in the ECC For Award and IDV component of Oracle Contract Lifecycle Management for Public Sector allows an authenticated attacker to gain full system takeover.
Executive summary
A critical vulnerability in Oracle Contract Lifecycle Management for Public Sector V16 permits a low privileged attacker to achieve full system takeover via network access.
Vulnerability
This vulnerability affects the ECC For Award and IDV component and is reachable via HTTP. It requires the attacker to hold low privileges to execute the attack, which can lead to a complete compromise of the affected software.
Business impact
The potential for a total system takeover poses an extreme risk to the confidentiality, integrity, and availability of critical contract data. With a CVSS score of 8.8, this high severity flaw could result in unauthorized modification of legal agreements, exfiltration of sensitive public sector information, and significant operational disruption.
Remediation
Immediate Action: Review the official Oracle security advisory at https://www.oracle.com/security-alerts/cspusep2026.html and apply the necessary security updates or patches as soon as they are released by the vendor.
Proactive Monitoring: Monitor network and application logs for unusual HTTP requests targeting the ECC For Award and IDV component, particularly those initiated by low privileged service accounts.
Compensating Controls: Implement strict access control lists and use a Web Application Firewall (WAF) to filter malicious traffic patterns directed at the vulnerable component until a vendor patch is applied.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the high CVSS score and the potential for full system compromise, this vulnerability represents a significant security risk. Administrators must prioritize applying vendor-supplied updates immediately upon availability to prevent unauthorized access and potential data breaches.
More Oracle CVEs all →
History
- Collected by CVE Brief via github
- Held for re-check analysis graded thin
- Analyst report written
Sources
- Oracle Advisory Vendor advisory