Junglewise Threat Intelligence

CVE-2026-61114: Oracle E-Business Suite compromise in Application Object Library

CVE-2026-61114 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle Application Object Library. Vendors: Oracle.

Executive brief

A security vulnerability exists in the Oracle Application Object Library, a core component of the Oracle E-Business Suite used for managing application data and security. An attacker with low-level access to the corporate network could exploit this flaw to take full control of the library. This could lead to unauthorized access to sensitive business data, disruption of operations, and a total compromise of the affected application environment.

Technical details

This vulnerability resides in the DB Privileges component of the Oracle Application Object Library within Oracle E-Business Suite. It is classified as a high-complexity exploit that allows a low-privileged attacker with network access via HTTP to compromise the component. Successful exploitation can result in a complete takeover of the Oracle Application Object Library, impacting confidentiality, integrity, and availability. The vulnerability affects supported versions 12.2.3 through 12.2.15. Oracle has addressed this issue in the July 2026 Critical Patch Update.

Affected products

  • Oracle Application Object Library (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed

References

Related threats