Junglewise Threat Intelligence

CVE-2026-61125: Oracle Configure to Order information disclosure in Supply to Order Workbench

CVE-2026-61125 · Severity: high · CVSS 7.7 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Supply to Order Workbench component of Oracle E-Business Suite's Configure to Order product. This tool is used by businesses to manage complex manufacturing and fulfillment processes. An attacker with basic user credentials could exploit this flaw to gain unauthorized access to sensitive business data, potentially impacting other integrated Oracle systems.

Technical details

This vulnerability affects the Supply to Order Workbench component of Oracle Configure to Order (versions 12.2.3 through 12.2.15). It is classified as an information disclosure flaw that is easily exploitable via the network using HTTP. A successful exploit requires low-privileged authentication but can lead to a scope change, meaning the attacker may gain unauthorized access to data beyond the immediate Configure to Order environment. The impact is primarily on confidentiality, potentially resulting in complete access to all data accessible by the component. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle Corporation Oracle Configure to Order 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats