Junglewise Threat Intelligence

CVE-2026-61012: Oracle Time and Labor data manipulation in Internal Operations

CVE-2026-61012 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle Time and Labor. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in Oracle Time and Labor, a component of the Oracle E-Business Suite used by organizations to manage employee hours and workforce scheduling. A low-privileged user could exploit this flaw to delete or modify critical business data and disrupt the availability of the time-tracking service. This could lead to significant payroll inaccuracies, loss of labor records, and operational delays.

Technical details

This vulnerability affects the Internal Operations component of Oracle Time and Labor within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can achieve unauthorized creation, deletion, or modification of critical data accessible to the application. Additionally, the exploit can be used to cause a partial denial of service (DoS), impacting the availability of the labor management system. The vulnerability has been addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Time and Labor 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats