
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-62490 is an information disclosure vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite, specifically within the Internal Operations component. It affects supported versions 12.2.3 through 12.2.15 and was published on July 21, 2026, as part of Oracle's July 2026 Critical Patch Update. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium severity), reflecting a network-accessible but difficult-to-exploit flaw requiring low privileges (Oracle CPU Jul 2026, Github Advisory).
The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), indicating that the Internal Operations component of Oracle Contracts Integration improperly exposes sensitive data to actors not authorized to access it. Exploitation requires a low-privileged attacker with network access via HTTP and involves high attack complexity, meaning specific conditions or configurations must be met for a successful attack. No user interaction is required, and the scope remains unchanged, limiting the blast radius to the affected component. No public technical write-ups or proof-of-concept code have been identified at this time (Github Advisory, Oracle CPU Jul 2026).
Successful exploitation results exclusively in a confidentiality impact — there is no integrity or availability impact. An attacker could gain unauthorized access to critical data or achieve complete access to all data accessible within Oracle Contracts Integration, which may include sensitive contract terms, financial data, and internal operational records. The scope is unchanged, meaning the impact is confined to the Oracle Contracts Integration component and does not directly enable lateral movement to other systems (Oracle CPU Jul 2026, Github Advisory).
Oracle has addressed this vulnerability as part of the July 2026 Critical Patch Update (CPU). Organizations running Oracle E-Business Suite versions 12.2.3 through 12.2.15 should apply the relevant patches from the CPU immediately. As a temporary workaround, Oracle recommends restricting network access to the Oracle Contracts Integration component via HTTP using firewall rules and network segmentation, and applying the principle of least privilege to user accounts accessing this module. Oracle strongly advises against relying on workarounds as a long-term solution (Oracle CPU Jul 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."