Junglewise Threat Intelligence

CVE-2026-61101: Oracle MES for Process Manufacturing data compromise in Internal Operations

CVE-2026-61101 · Severity: high · CVSS 8.2 · Published 2026-07-21

Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability in Oracle's manufacturing execution software could allow an unauthorized person to access or modify sensitive production data. This software is used to manage and track manufacturing processes, and a successful exploit could lead to the theft of proprietary information or unauthorized changes to operational records. The attack requires a legitimate user to perform a specific action, such as clicking a malicious link, while logged into the system.

Technical details

This vulnerability exists in the Internal Operations component of Oracle MES for Process Manufacturing (part of Oracle E-Business Suite). It is an unauthenticated, network-based attack via HTTP that requires human interaction (UI:R) from a legitimate user. The vulnerability is characterized by a 'scope change' (S:C), meaning an exploit can impact components beyond the immediate software. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of data. Affected versions include 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle Corporation MES for Process Manufacturing 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.

References