Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-87155

CVE-2026-87155: Oracle Product Hub Auth Bypass Vulnerability

CVE-2026-87155 is an authentication bypass vulnerability in Oracle Product Hub that enables low-privileged attackers to take over the system. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-87155 Overview

CVE-2026-87155 is a privilege escalation vulnerability in the Oracle Product Hub product of Oracle E-Business Suite, specifically within the Internal Operations component. The flaw affects supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access over HTTP can exploit this weakness to fully compromise Oracle Product Hub. Successful exploitation results in complete takeover of the affected instance, impacting confidentiality, integrity, and availability. The vulnerability is categorized under CWE-269: Improper Privilege Management.

Critical Impact

An authenticated attacker with minimal privileges can escalate access over the network and take full control of Oracle Product Hub, gaining the ability to read, modify, and disrupt product master data.

Affected Products

  • Oracle E-Business Suite Product Hub 12.2.3
  • Oracle E-Business Suite Product Hub versions 12.2.4 through 12.2.14
  • Oracle E-Business Suite Product Hub 12.2.15

Discovery Timeline

  • 2026-09-15 - CVE-2026-87155 published to NVD
  • 2026-09-17 - Last updated in NVD database

Technical Details for CVE-2026-87155

Vulnerability Analysis

CVE-2026-87155 resides in the Internal Operations component of Oracle Product Hub, part of the Oracle E-Business Suite (EBS). The flaw allows a low-privileged authenticated user to elevate access and compromise the entire application. Oracle Product Hub centralizes master data for products, items, and catalogs across the enterprise. Compromise of this component exposes proprietary product records, pricing structures, supplier associations, and downstream ERP workflows.

Because the attack vector is network-based over HTTP and exploitation complexity is low, any authenticated user account within the EBS environment can serve as a launch point. The Exploit Prediction Scoring System places this issue in the upper range of network-exploitable EBS defects tracked by Oracle in the September 2026 alert cycle.

Root Cause

The vulnerability maps to CWE-269: Improper Privilege Management. The Internal Operations component fails to correctly enforce privilege boundaries between low-privileged users and administrative functionality. As a result, an attacker can invoke operations that should be reserved for privileged roles. Oracle has not publicly released the specific code-level defect. See the Oracle Security Alert CSPUSEP2026 for authoritative details.

Attack Vector

Exploitation requires network reachability to the Oracle Product Hub HTTP endpoint and valid credentials for any low-privileged EBS account. The attacker submits crafted HTTP requests to Internal Operations functions that fail to validate the caller's authorization. Successful requests grant the attacker elevated privileges within the application, enabling data exfiltration, unauthorized modification of product master data, and denial of service against the Product Hub instance.

No public proof-of-concept exploit has been observed, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog at the time of publication.

Detection Methods for CVE-2026-87155

Indicators of Compromise

  • Unexpected HTTP requests to Oracle Product Hub Internal Operations endpoints originating from low-privileged user sessions.
  • Anomalous privilege changes, new administrator role assignments, or unauthorized modifications to FND_USER and FND_USER_ROLE_ASSIGNMENTS records.
  • Bulk read, export, or modification of item master data outside of scheduled batch windows.

Detection Strategies

  • Review Oracle EBS FND_LOG_MESSAGES and application server access logs for HTTP calls to Product Hub Internal Operations by accounts that historically lack administrative context.
  • Correlate authentication events with subsequent privileged operations to identify vertical privilege escalation patterns.
  • Baseline normal Product Hub API usage per role and alert on deviations, especially for accounts with minimal responsibilities.

Monitoring Recommendations

  • Forward Oracle EBS application, database audit, and web tier logs to a centralized SIEM for correlation with identity telemetry.
  • Enable Oracle Fine-Grained Auditing (FGA) on sensitive Product Hub tables to capture read and write access by low-privileged accounts.
  • Monitor outbound traffic from EBS application servers for unusual data volumes that may indicate exfiltration of product master data.

How to Mitigate CVE-2026-87155

Immediate Actions Required

  • Apply the fixes referenced in the Oracle Security Alert CSPUSEP2026 to all Oracle Product Hub instances running versions 12.2.3 through 12.2.15.
  • Inventory all EBS environments, including non-production, and prioritize internet-exposed or partner-accessible tiers.
  • Audit accounts with access to Product Hub and revoke unused or dormant low-privileged credentials.

Patch Information

Oracle addressed CVE-2026-87155 in the September 2026 Critical Security Alert for Oracle E-Business Suite. Refer to the Oracle Security Alert CSPUSEP2026 for the specific patch identifiers, applicability matrix, and installation prerequisites for versions 12.2.3 through 12.2.15.

Workarounds

  • Restrict network access to Oracle Product Hub HTTP endpoints using firewall rules, reverse proxies, or a web application firewall until patches are applied.
  • Enforce multi-factor authentication and strong password policies on all EBS accounts to raise the cost of credential compromise.
  • Reduce role assignments for accounts that do not require Product Hub access, minimizing the pool of low-privileged users that could exploit the flaw.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.