Junglewise Threat Intelligence

CVE-2026-61102: Oracle Banking Trade Finance data compromise in Infrastructure

CVE-2026-61102 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Banking Trade Finance, a platform used by financial institutions to manage trade finance operations. An attacker with basic user access can exploit this flaw over the network to view, modify, or delete sensitive banking data. This could lead to significant data breaches, unauthorized financial transactions, or the corruption of critical business records.

Technical details

A vulnerability in the Infrastructure component of Oracle Banking Trade Finance (versions 14.6.0 through 14.8.0) allows for unauthorized data access and modification. The flaw is categorized as easily exploitable and requires only low-privileged user credentials. An attacker can execute the exploit over the network via HTTP without any user interaction. Successful exploitation grants the attacker the ability to create, delete, or modify critical data, as well as gain full read access to all data accessible by the application. The vulnerability has a CVSS 3.1 base score of 8.1, impacting confidentiality and integrity but not availability.

Affected products

  • Oracle Banking Trade Finance 14.6.0-14.8.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats