Junglewise Threat Intelligence

CVE-2026-61217: Oracle Security Service data compromise in Oracle SSL API

CVE-2026-61217 · Severity: medium · CVSS 6.4 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Security Service component of Oracle Fusion Middleware, which manages secure communications and identity. A low-privileged attacker could potentially gain unauthorized access to, modify, or delete sensitive data managed by the service. Exploiting this flaw is difficult as it requires a legitimate user to perform a specific action and relies on specific network conditions.

Technical details

This vulnerability affects the Oracle SSL API within Oracle Security Service version 12.2.1.4.0. It is classified as difficult to exploit (High Attack Complexity) and requires a low-privileged attacker to have network access via TLS. A successful exploit requires human interaction from a person other than the attacker (User Interaction Required). If successful, the attacker can achieve unauthorized creation, deletion, or modification of all data accessible to the Oracle Security Service, as well as full read access to that data. The impact is limited to Confidentiality and Integrity, with no reported impact on Availability.

Affected products

  • Oracle Security Service (Oracle SSL API) 12.2.1.4.0

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.

References