PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87163 Oracle CVE debrief

A vulnerability in Oracle Purchasing of Oracle E-Business Suite (component: Other issue) with a CVSS 3.1 Base Score of 8.8 was made public on 2026-09-15. The vulnerability affects versions 12.2.3-12.2.15 and can be easily exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of Oracle Purchasing. This high-severity vulnerability requires immediate attention from defenders managing Oracle E-Business Suite, particularly those responsible for Oracle Purchasing, to assess exposure and prioritize remediation.

Vendor
Oracle
Product
Purchasing
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-22
Advisory published
2026-09-15
Advisory updated
2026-09-22

Who should care

Defenders responsible for Oracle E-Business Suite, specifically those managing Oracle Purchasing, should assess exposure and prioritize remediation due to the high severity and potential impact of the vulnerability.

Why it matters

CVE-2026-87163 is a high-severity vulnerability in Oracle Purchasing of Oracle E-Business Suite that can be easily exploited, potentially leading to a takeover. Defenders managing Oracle Purchasing should verify exposure, assess security controls, and prioritize remediation.

  • Potential takeover of Oracle Purchasing, impacting confidentiality, integrity, and availability
  • Requires verification of affected versions 12.2.3-12.2.15 in use
  • Necessitates assessment of network access controls to limit exploitation
  • Prioritization of remediation based on CVSS score and potential business impact

Technical summary

The vulnerability in Oracle Purchasing of Oracle E-Business Suite (component: Other issue) affects versions 12.2.3-12.2.15. It has a CVSS 3.1 Base Score of 8.8, indicating high severity. The vulnerability can be easily exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of Oracle Purchasing. Defenders should focus on verifying exposure of affected versions, assessing current security controls, and prioritizing remediation efforts based on the CVSS score and potential business impact.

Defensive priority

Defenders should prioritize verifying exposure of Oracle Purchasing versions 12.2.3-12.2.15 and assessing the effectiveness of current security controls.

Recommended defensive actions

  • Verify Oracle Purchasing versions 12.2.3-12.2.15 are not in use or apply vendor patches
  • Assess network access controls to limit low-privileged attacker access via HTTP
  • Review and enhance monitoring for potential takeover attempts of Oracle Purchasing
  • Conduct an inventory of affected Oracle Purchasing deployments
  • Review change management processes for timely application of security patches
  • Track and document remediation progress for auditing purposes
  • Consider compensating controls for exposed systems while remediation is in progress

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score, affected versions, and potential impact. However, additional information on exploitation or specific attacks is not provided in the source corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87163 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87163

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87163 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87163

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.