Junglewise Threat Intelligence

CVE-2026-61200: Oracle Labor Distribution unauthorized data access in Internal Operations

CVE-2026-61200 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Labor Distribution. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Labor Distribution, a tool used within the Oracle E-Business Suite to manage labor costs and schedules. An attacker with basic user access to the network can exploit this flaw to view, modify, or delete sensitive labor-related data. This could lead to unauthorized changes in financial records or the exposure of internal operational information.

Technical details

This vulnerability affects the Internal Operations component of Oracle Labor Distribution within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an improper access control or data validation issue that is easily exploitable over the network via HTTP. An attacker requires low-level privileges (authenticated user) to execute the exploit. Successful exploitation allows the attacker to perform unauthorized Create, Read, Update, and Delete (CRUD) operations on a subset of the application's data. The vulnerability has been addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Labor Distribution 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats