Executive brief
A vulnerability in the Internal Operations component of Oracle Process Manufacturing Systems could allow an authorized user with low-level permissions to take full control of the system. This software is used to manage complex manufacturing processes, and a compromise could lead to the theft of sensitive production data, disruption of manufacturing operations, or unauthorized changes to product specifications. The issue affects Oracle E-Business Suite versions 12.2.3 through 12.2.15.
Technical details
A vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Systems (part of Oracle E-Business Suite). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific vulnerability class (e.g., injection or broken access control) is not explicitly named in the advisory, the impact is rated as a complete compromise of confidentiality, integrity, and availability (takeover). The issue affects versions 12.2.3 through 12.2.15. Organizations should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Process Manufacturing Systems (E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-61010 by Oracle