Junglewise Threat Intelligence

CVE-2026-61113: Oracle E-Business Suite data compromise in Application Object Library

CVE-2026-61113 · Severity: high · CVSS 7.4 · Published 2026-07-21

Technologies: Oracle Application Object Library. Vendors: Oracle.

Executive brief

A vulnerability exists in the core component of Oracle E-Business Suite's Application Object Library, which manages fundamental system functions and data access. An attacker could exploit this to gain unauthorized access to sensitive business data or modify critical records, potentially leading to data theft or operational disruption. While the attack is difficult to execute, it requires no user interaction or prior login credentials.

Technical details

This vulnerability affects the Core component of the Oracle Application Object Library within Oracle E-Business Suite. It is classified as a high-complexity attack (AC:H) that can be initiated by an unauthenticated attacker over the network via HTTP. Successful exploitation allows for unauthorized creation, deletion, or modification of critical data, as well as full read access to all data accessible by the Application Object Library. The vulnerability has a CVSS 3.1 base score of 7.4, impacting both confidentiality and integrity, though it does not directly impact service availability. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle Application Object Library (E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed: NVD published the CVE record.

References

Related threats