Junglewise Threat Intelligence

CVE-2026-61105: Oracle Banking Trade Finance data compromise in Infrastructure

CVE-2026-61105 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Banking Trade Finance, a platform used by financial institutions to manage trade operations, contains a security vulnerability in its infrastructure component. A user with basic login credentials can exploit this flaw over the network to view, modify, or delete sensitive financial data. This could lead to significant data breaches, unauthorized transactions, or the corruption of critical banking records.

Technical details

A vulnerability exists in the Infrastructure component of Oracle Banking Trade Finance versions 14.6.0 through 14.8.0. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized creation, deletion, or modification of critical data, as well as gain full read access to all data accessible by the application. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity without affecting system availability. Users should refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Banking Trade Finance 14.6.0-14.8.0

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle and NVD

References

Related threats