Junglewise Threat Intelligence

CVE-2026-61110: Oracle Applications DBA takeover via ADPatch in E-Business Suite

CVE-2026-61110 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Applications Dba. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Applications DBA component of the Oracle E-Business Suite, which is used by administrators to manage and patch enterprise resource planning (ERP) systems. An attacker with low-level user access can exploit this flaw over the network to take full control of the database administration tools. This could lead to a complete compromise of the business suite, including the theft of sensitive corporate data or disruption of critical business operations.

Technical details

This vulnerability is located in the ADPatch component of the Oracle Applications DBA product within Oracle E-Business Suite. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. While the specific CWE is not provided in the advisory, the impact is a complete compromise of Confidentiality, Integrity, and Availability (CIA triad), effectively allowing an attacker to take over the Oracle Applications DBA environment. The vulnerability affects supported versions 12.2.3 through 12.2.15. Organizations should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Oracle Applications DBA (Oracle E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed: NVD published the CVE record.

References

Related threats