LiveActive security incident?Get immediate response
CVE Record

CVE-2026-62546: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utili...

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

CriticalCVSS 9.1Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

CVE-2026-62546 is a critical Oracle E-Business Suite issue in Oracle Applications Framework Web Utilities. A highly privileged user with HTTP network access could compromise the framework, potentially taking it over and affecting confidentiality, integrity, and availability.

Executive priority

Prioritize remediation for internet-facing or broadly reachable Oracle E-Business Suite environments. The attacker must already be highly privileged, but successful compromise could produce full framework takeover and wider product impact.

Technical view

Oracle describes an easily exploitable CWE-284 access-control issue in Oracle Applications Framework, affecting supported E-Business Suite versions 12.2.8 through 12.2.15. The CVSS 3.1 score is 9.1 with network access, low complexity, high privileges, no user interaction, changed scope, and high CIA impact.

Likely exposure

Organizations running Oracle E-Business Suite 12.2.8-12.2.15 with Oracle Applications Framework reachable over HTTP should treat exposure as relevant, especially where high-privileged accounts can access the application.

Exploitation context

The provided sources do not show CISA KEV listing or confirmed active exploitation. The risk is still serious because Oracle rates exploitation as easy once the attacker has high privileges and HTTP reachability.

Researcher notes

Key constraints are PR:H and HTTP network access. Scope change and high CIA impact make this more than a single-component issue. The public bundle does not provide exploit mechanics, patch identifiers, or evidence of exploitation.

Mitigation direction

  • Review Oracle's July 2026 Critical Patch Update guidance for this CVE.
  • Apply the applicable Oracle E-Business Suite patches from vendor guidance.
  • Restrict HTTP access to Oracle E-Business Suite administrative interfaces.
  • Review high-privileged account access and remove unnecessary privileges.
  • Increase monitoring for unusual privileged activity in affected environments.

Validation and detection

  • Inventory Oracle E-Business Suite versions and identify 12.2.8-12.2.15 systems.
  • Confirm whether Oracle Applications Framework Web Utilities are present and reachable.
  • Verify applicable Oracle CPU patches are installed on each affected instance.
  • Review authentication and authorization controls for high-privileged accounts.
  • Check application logs for unusual privileged HTTP activity since July 21, 2026.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-284: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-62546 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.1 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.1CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H2.36oracle

Vulnerability scoring details

Base CVSS 3.1 score

9.1Critical
CVSS 3.1 vector shape for CVE-2026-62546Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Oracle CorporationOracle Applications Framework12.2.8Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-284 · source CWE mapping

Improper Access Control

Improper Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.