
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-62487 is a Cross-Site Request Forgery (CSRF) vulnerability in the Oracle Contracts Integration component (Internal Operations) of Oracle E-Business Suite. It affects supported versions 12.2.3 through 12.2.15 and was published on July 21, 2026, as part of Oracle's July 2026 Critical Patch Update. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (Oracle CPU Jul 2026, Github Advisory).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), meaning the Oracle Contracts Integration application does not sufficiently verify whether HTTP requests were intentionally submitted by the authenticated user. An unauthenticated remote attacker can craft a malicious HTTP request that, when triggered by a victim user's browser session, performs unauthorized actions on the Oracle Contracts Integration application. The attack requires no privileges and has low complexity, but does require human interaction (a victim user must visit or interact with attacker-controlled content). The changed scope indicates that a successful attack can impact components beyond the directly vulnerable Oracle Contracts Integration module (Github Advisory, Oracle CPU Jul 2026).
Successful exploitation allows an unauthenticated attacker to perform unauthorized update, insert, or delete operations on a subset of Oracle Contracts Integration accessible data, as well as gain unauthorized read access to some of that data. There is no availability impact, but the scope change means that other Oracle E-Business Suite products sharing the same environment may also be affected. Sensitive contract-related business data could be exposed or tampered with, potentially impacting business operations and data integrity (Oracle CPU Jul 2026, Github Advisory).
Oracle has released patches for CVE-2026-62487 as part of the July 2026 Critical Patch Update. Organizations running Oracle E-Business Suite versions 12.2.3 through 12.2.15 should apply the relevant patches immediately by following the Oracle E-Business Suite patch availability documentation. As a temporary measure, restricting network access to Oracle E-Business Suite to trusted internal networks and enforcing strict referrer/origin validation at the web application firewall layer may reduce risk, but these are not substitutes for patching. Oracle strongly recommends applying Critical Patch Update patches as soon as possible (Oracle CPU Jul 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."