PatchSiren cyber security CVE debrief
CVE-2026-87153 Oracle Corporation CVE debrief
A high-severity vulnerability exists in Oracle Product Hub, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-87153, allows a low-privileged attacker with network access via HTTP to compromise the Oracle Product Hub. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Product Hub accessible data, as well as unauthorized access to critical data or complete access to all Oracle Product Hub accessible data.
- Vendor
- Oracle Corporation
- Product
- Oracle Product Hub
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-18
Who should care
Defenders and administrators responsible for Oracle E-Business Suite and Oracle Product Hub deployments should assess exposure and prioritize remediation. This includes reviewing current versions, access controls, and network configurations to minimize the risk of exploitation.
Why it matters
CVE-2026-87153 is a high-severity vulnerability in Oracle Product Hub that allows low-privileged attackers to potentially access and modify critical data. Defenders should prioritize patching, restrict network access, and monitor for suspicious activity. The vulnerability's impact requires verification in specific deployment contexts, and remediation is crucial to prevent data compromise.
- Potential unauthorized creation, deletion, or modification access to critical data or all Oracle Product Hub accessible data
- Potential unauthorized access to critical data or complete access to all Oracle Product Hub accessible data
- Requires verification of affected versions and exposure in specific deployment contexts
- Remediation priority is high due to the potential for significant data compromise
Technical summary
The vulnerability exists in the Internal Operations component of Oracle Product Hub, affecting versions 12.2.3-12.2.15. It has a CVSS 3.1 Base Score of 8.1, indicating high severity. The vulnerability allows low-privileged attackers with network access via HTTP to compromise the Oracle Product Hub, potentially leading to unauthorized data access and modification. Defenders should prioritize patching or mitigating this vulnerability, especially in environments where low-privileged access is common, and review compensating controls for exposed systems while remediation is scheduled and verified.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability, especially in environments where low-privileged access is common.
Recommended defensive actions
- Apply patches or updates provided by Oracle to address the vulnerability
- Restrict network access to the Oracle Product Hub to minimize the attack surface
- Monitor for suspicious activity related to unauthorized data access or modification
- Review and update access controls to ensure low-privileged users have only necessary permissions
- Perform vulnerability scanning to identify potentially affected systems
- Review system logs for signs of exploitation
- Implement additional security measures such as Web Application Firewalls (WAFs) to detect and prevent attacks
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, including its CVSS score and vector. Oracle's security alert page is also referenced for further information. The vulnerability affects Oracle Product Hub versions 12.2.3-12.2.15, and defenders should verify the affected scope and exposure in specific deployment contexts. Evidence limits suggest that additional information may be necessary to fully understand the vulnerability's impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87153 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87153
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87153 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87153
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.