Oracle Contract Lifecycle Management for Public Sector: takeover via ECC For...
High8.8CVE-2026-87165 · Published Sep 15, 2026 · updated Sep 17, 2026
Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: ECC For Award and IDV). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public Sector. Successful attacks of this vulnerability can result in takeover of Oracle Contract Lifecycle Management for Public Sector. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Oracle Contract Lifecycle Management for Public Sector Product | <= V16 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-269
More Oracle advisories
All Oracle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | Oracle GraalVM for JDK: takeover via Compiler | High8.1 | No fix yet |
| Sep 15 | Oracle GraalVM for JDK: data tampering via Compiler | High7.0 | No fix yet |
| Sep 15 | Oracle GraalVM for JDK: takeover via Compiler | High8.1 | No fix yet |
| Sep 15 | Oracle VM VirtualBox: flaw in Core | Low3.2 | No fix yet |
| Sep 15 | Oracle VM VirtualBox: denial of service via Core | Medium6.0 | No fix yet |
| Sep 15 | Oracle GraalVM: takeover via Compiler | High8.1 | No fix yet |