Junglewise Threat Intelligence

CVE-2026-61006: Oracle Process Manufacturing Logistics compromise in Internal Operations

CVE-2026-61006 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle Process Manufacturing Logistics. Vendors: Oracle.

Executive brief

A vulnerability in Oracle Process Manufacturing Logistics, a component of the Oracle E-Business Suite used for managing industrial production and supply chains, allows an attacker to take full control of the system. An exploit could lead to the total loss of confidentiality, integrity, and availability of manufacturing data and operations. While the attack requires high-level administrative privileges, it can be executed remotely over the network.

Technical details

This vulnerability affects the Internal Operations component of Oracle Process Manufacturing Logistics within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as easily exploitable, requiring network access via HTTP and high-privileged credentials (PR:H). A successful exploit allows an attacker to achieve a complete takeover of the affected component, impacting confidentiality, integrity, and availability. The vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Process Manufacturing Logistics 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats