Junglewise Threat Intelligence

CVE-2026-61060: Oracle E-Business Suite data manipulation in Secure Enterprise Search

CVE-2026-61060 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite Secure Enterprise Search, a tool used by organizations to search across enterprise data, contains a vulnerability in its Search Integration Engine. An attacker with basic user credentials can exploit this over the network to view, modify, or delete certain business data. This could lead to unauthorized data manipulation or the exposure of sensitive internal information.

Technical details

This vulnerability exists in the Search Integration Engine component of Oracle E-Business Suite Secure Enterprise Search. It is classified as an easily exploitable flaw that can be triggered by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized updates, insertions, or deletions of a subset of data, as well as unauthorized read access to specific data sets. The vulnerability has a CVSS 3.1 base score of 5.4, reflecting impacts on confidentiality and integrity but not availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle E-Business Suite Secure Enterprise Search 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.

References

Related threats