Junglewise Threat Intelligence

CVE-2026-61019: Oracle Customers Online data compromise in Internal Operations

CVE-2026-61019 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Customers Online, a tool used by businesses to manage customer data within the Oracle E-Business Suite. An attacker with basic user access can exploit this flaw over the network to view, modify, or delete sensitive customer information. This could lead to significant data breaches or the corruption of critical business records.

Technical details

This vulnerability affects the Internal Operations component of Oracle Customers Online within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. Successful exploitation allows an attacker to achieve high confidentiality and integrity impacts, including the unauthorized creation, deletion, or modification of all accessible data within the product. The vulnerability does not impact availability (A:N) and does not require user interaction. Fixes are typically delivered via Oracle's Critical Patch Update (CPU) program.

Affected products

  • Oracle Corporation Customers Online (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and security alert.

References

Related threats