Junglewise Threat Intelligence

CVE-2026-61090: Oracle Project Foundation takeover via local infrastructure access

CVE-2026-61090 · Severity: high · CVSS 7.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability in Oracle Project Foundation, a component of the Oracle E-Business Suite used for project management and accounting, allows an attacker with existing access to the underlying server to take full control of the application. This could lead to the unauthorized access, modification, or deletion of sensitive project and financial data. The issue affects versions 12.2.3 through 12.2.15 of the software.

Technical details

This vulnerability exists in the 'Miscellaneous' component of Oracle Project Foundation within Oracle E-Business Suite. It is classified as a local exploit, requiring the attacker to have existing logon credentials to the infrastructure where the application executes. The vulnerability is described as easily exploitable and does not require user interaction. A successful exploit results in a complete compromise (High Confidentiality, Integrity, and Availability impact) of the Oracle Project Foundation component. Affected versions range from 12.2.3 to 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Project Foundation 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats