CVE-2026-62540: High severity Oracle Oracle Cost Management vulnerability
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Oracle Cost Management deployments using the Cost Planning component on supported Oracle E-Business Suite versions 12.2.3 through 12.2.15 are affected. Exploitation requires network access to the service over HTTP.
What access does an attacker need to exploit it?
An attacker must already have high privileges and network access via HTTP. No user interaction is required, and the attack complexity is low.
What is the potential impact of successful exploitation?
Successful exploitation can result in takeover of Oracle Cost Management, with high impacts to confidentiality, integrity, and availability.