Junglewise Threat Intelligence

CVE-2026-61005: Oracle Process Manufacturing Logistics data compromise in Internal Operations

CVE-2026-61005 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Process Manufacturing Logistics. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle E-Business Suite's Process Manufacturing Logistics module, which manages supply chain and internal operations. An authorized user with low-level permissions can exploit this flaw to gain full access to sensitive business data. This could result in the unauthorized viewing, modification, or deletion of critical operational records, potentially disrupting manufacturing workflows and compromising data integrity.

Technical details

This vulnerability affects the Internal Operations component of Oracle Process Manufacturing Logistics within Oracle E-Business Suite. It is classified as an easily exploitable flaw that requires network access via HTTP and low-privileged user authentication. The root cause is not specified, but the impact allows for unauthorized Confidentiality and Integrity compromises. Attackers can achieve full read and write access to all data managed by the affected component. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Process Manufacturing Logistics 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats