Junglewise Threat Intelligence

CVE-2026-61044: Oracle Production Scheduling unauthorized data access in Internal Operations

CVE-2026-61044 · Severity: medium · CVSS 4.7 · Published 2026-07-21

Technologies: Oracle Production Scheduling. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Production Scheduling, a component of the Oracle E-Business Suite used for managing manufacturing and supply chain operations. A high-privileged user could exploit this flaw to gain unauthorized access to sensitive data or disrupt scheduling operations. While the risk is mitigated by the requirement for high-level administrative access, a successful attack could lead to data manipulation or a partial service outage.

Technical details

This vulnerability affects the Internal Operations component of Oracle Production Scheduling within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires high privileges (PR:H) and network access via HTTP (AV:N). An attacker with these credentials can perform unauthorized data modifications (insert, update, delete), read a subset of accessible data, and cause a partial denial of service. The vulnerability has a CVSS 3.1 base score of 4.7, reflecting low impacts on confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle Production Scheduling 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed

References

Related threats