PatchSiren cyber security CVE debrief
CVE-2026-87163 Oracle CVE debrief
A vulnerability in Oracle Purchasing of Oracle E-Business Suite (component: Other issue) with a CVSS 3.1 Base Score of 8.8 was made public on 2026-09-15. The vulnerability affects versions 12.2.3-12.2.15 and can be easily exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of Oracle Purchasing. This high-severity vulnerability requires immediate attention from defenders managing Oracle E-Business Suite, particularly those responsible for Oracle Purchasing, to assess exposure and prioritize remediation.
- Vendor
- Oracle
- Product
- Purchasing
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-22
Who should care
Defenders responsible for Oracle E-Business Suite, specifically those managing Oracle Purchasing, should assess exposure and prioritize remediation due to the high severity and potential impact of the vulnerability.
Why it matters
CVE-2026-87163 is a high-severity vulnerability in Oracle Purchasing of Oracle E-Business Suite that can be easily exploited, potentially leading to a takeover. Defenders managing Oracle Purchasing should verify exposure, assess security controls, and prioritize remediation.
- Potential takeover of Oracle Purchasing, impacting confidentiality, integrity, and availability
- Requires verification of affected versions 12.2.3-12.2.15 in use
- Necessitates assessment of network access controls to limit exploitation
- Prioritization of remediation based on CVSS score and potential business impact
Technical summary
The vulnerability in Oracle Purchasing of Oracle E-Business Suite (component: Other issue) affects versions 12.2.3-12.2.15. It has a CVSS 3.1 Base Score of 8.8, indicating high severity. The vulnerability can be easily exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of Oracle Purchasing. Defenders should focus on verifying exposure of affected versions, assessing current security controls, and prioritizing remediation efforts based on the CVSS score and potential business impact.
Defensive priority
Defenders should prioritize verifying exposure of Oracle Purchasing versions 12.2.3-12.2.15 and assessing the effectiveness of current security controls.
Recommended defensive actions
- Verify Oracle Purchasing versions 12.2.3-12.2.15 are not in use or apply vendor patches
- Assess network access controls to limit low-privileged attacker access via HTTP
- Review and enhance monitoring for potential takeover attempts of Oracle Purchasing
- Conduct an inventory of affected Oracle Purchasing deployments
- Review change management processes for timely application of security patches
- Track and document remediation progress for auditing purposes
- Consider compensating controls for exposed systems while remediation is in progress
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score, affected versions, and potential impact. However, additional information on exploitation or specific attacks is not provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87163 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87163
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87163 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87163
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.