Junglewise Threat Intelligence

CVE-2026-61050: Oracle Production Scheduling unauthorized data access in User Interface

CVE-2026-61050 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle Production Scheduling. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle Production Scheduling, a component of the Oracle E-Business Suite used for supply chain planning and manufacturing optimization. An attacker with basic user credentials could potentially gain unauthorized access to sensitive business data. While the attack is difficult to execute, a successful exploit could lead to the exposure of critical production and scheduling information.

Technical details

This vulnerability affects the User Interface component of Oracle Production Scheduling within Oracle E-Business Suite. It is classified as a confidentiality-impacting bug that allows a low-privileged attacker with network access via HTTP to compromise the system. The attack complexity is rated as high, suggesting that specific conditions or significant effort are required to successfully exploit the flaw. If successful, an attacker can achieve unauthorized access to critical data or complete access to all data accessible by the Production Scheduling component. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Production Scheduling 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats