Junglewise Threat Intelligence

CVE-2026-61030: Oracle Process Manufacturing Product Development data compromise in Internal Operations

CVE-2026-61030 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle, Oracle Corporation.

Executive brief

A security vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Product Development, a tool used by manufacturers to manage product recipes and formulas. An attacker with basic user access can exploit this flaw over the network to view, modify, or delete sensitive manufacturing data. This could lead to the loss of proprietary product information or unauthorized changes to critical production specifications.

Technical details

This vulnerability affects the Internal Operations component of Oracle Process Manufacturing Product Development within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires network access via HTTP and low-level user privileges (PR:L). An attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as full read access to all data accessible by the component. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle Corporation Oracle Process Manufacturing Product Development 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Initial publication by Oracle and NVD

References

Related threats