Junglewise Threat Intelligence

CVE-2026-61041: Oracle Demantra Demand Management takeover via Product Security component

CVE-2026-61041 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Demantra Demand Management, a tool used by businesses to forecast and manage supply chain demand, contains a critical security vulnerability. An attacker with low-level access to the network can exploit this flaw to take complete control of the system. Because this component is integrated with other business systems, a successful attack could also allow the intruder to compromise additional parts of the corporate infrastructure, leading to significant data loss or operational disruption.

Technical details

A critical vulnerability exists in the Product Security component of Oracle Demantra Demand Management (versions 12.2.3 through 12.2.15). The flaw is classified as easily exploitable and requires only low-privileged user credentials to execute over the network via HTTP. Successful exploitation results in a complete compromise of the Demantra environment (Confidentiality, Integrity, and Availability). Notably, the vulnerability carries a 'Scope Change' (S:C) designation, indicating that an attacker can leverage this flaw to impact resources beyond the immediate security scope of the Demantra application. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Demantra Demand Management 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats