Junglewise Threat Intelligence

CVE-2026-61051: Oracle E-Business Suite data manipulation in Concurrent Processing

CVE-2026-61051 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the BI Publisher Integration component of Oracle E-Business Suite's Concurrent Processing product. This system is used by organizations to manage background tasks and generate business reports. An attacker with low-level user credentials could exploit this flaw to view, modify, or delete sensitive business data and potentially disrupt reporting services.

Technical details

A vulnerability in the BI Publisher Integration component of Oracle Concurrent Processing (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to read, update, insert, or delete a subset of data accessible to the Concurrent Processing service. Additionally, the vulnerability can be used to cause a partial denial of service (DoS). The issue affects versions 12.2.3 through 12.2.15 and was addressed in the July 2026 Oracle Critical Patch Update.

Affected products

  • Oracle Corporation Concurrent Processing (BI Publisher Integration) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References