Vulnerability in Oracle Purchasing of Oracle E-Business Suite
CVE-2026-87166

8.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-87166?

The vulnerability in Oracle Purchasing within the Oracle E-Business Suite involves an easily exploitable flaw that enables low-privileged attackers with network access via HTTP to gain unauthorized access to sensitive data. Successful exploitation leads to the unauthorized creation, deletion, or modification of data across all accessible resources of Oracle Purchasing. This vulnerability poses significant risks related to both the confidentiality and integrity of critical information within the system.

Affected Version(s)

Oracle Purchasing 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.