Junglewise Threat Intelligence

CVE-2026-61047: Oracle Production Scheduling unauthorized data modification in Internal Operations

CVE-2026-61047 · Severity: low · CVSS 1.9 · Published 2026-07-21

Technologies: Oracle Production Scheduling. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Production Scheduling, a tool used within the Oracle E-Business Suite to manage manufacturing timelines and resource allocation. A highly privileged attacker with existing access to the underlying server infrastructure could potentially make unauthorized changes to scheduling data. While the impact is limited to minor data modifications and requires significant effort to exploit, it could affect the accuracy of production records.

Technical details

This vulnerability affects the Internal Operations component of Oracle Production Scheduling within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a low-severity issue because it requires the attacker to already possess high-level privileges and local logon access to the infrastructure where the software executes. Furthermore, the attack complexity is high, suggesting specific timing or environmental conditions are necessary for success. If exploited, an attacker can perform unauthorized updates, insertions, or deletions of certain data accessible to the application, impacting data integrity but not confidentiality or availability. The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Production Scheduling 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats