Junglewise Threat Intelligence

CVE-2026-61097: Oracle Banking Trade Finance Process Management security misconfiguration in Common component

CVE-2026-61097 · Severity: critical · CVSS 9.6 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Banking Trade Finance Process Management, a platform used by financial institutions to manage trade finance workflows, contains a critical security flaw. An attacker can exploit this vulnerability by tricking a legitimate user into performing a specific action, such as clicking a malicious link. If successful, the attacker could gain full access to sensitive banking data, modify or delete critical financial records, and cause service disruptions.

Technical details

A vulnerability in the Common component of Oracle Banking Trade Finance Process Management (versions 14.6.0 through 14.8.0) allows an unauthenticated remote attacker to compromise the system via HTTP. The flaw is characterized by a CVSS 3.1 score of 9.6, indicating a high impact on confidentiality and integrity with a scope change, suggesting a Cross-Site Scripting (XSS) or similar injection attack that can affect other integrated products. While the attack is easily exploitable over the network, it requires interaction from a user other than the attacker. Successful exploitation grants the attacker the ability to read, create, or delete all accessible data within the application and potentially cause a partial denial of service.

Affected products

  • Oracle Banking Trade Finance Process Management 14.6.0-14.8.0

Timeline

  • 2026-07-21: advisory: Published by Oracle in the July 2026 CPU

References