Junglewise Threat Intelligence

CVE-2026-61020: Oracle Customers Online unauthorized data access in Internal Operations

CVE-2026-61020 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in Oracle Customers Online, a component of the Oracle E-Business Suite used for managing customer data and internal operations. An attacker with basic user credentials can exploit this flaw over the network to gain full access to sensitive customer information. This could lead to the unauthorized viewing, modification, or deletion of critical business data, potentially impacting regulatory compliance and operational integrity.

Technical details

This vulnerability affects the Internal Operations component of Oracle Customers Online within Oracle E-Business Suite. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can leverage this vulnerability to bypass intended access controls, resulting in high impacts on confidentiality and integrity. Successful exploitation allows for the unauthorized creation, deletion, or modification of all accessible data within the product. The vulnerability does not impact system availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation E-Business Suite (Oracle Customers Online) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References