Executive brief
A vulnerability exists in Oracle Banking Origination, a platform used by financial institutions to manage the account opening and loan application process. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive banking data. This could lead to unauthorized changes to customer records or the exposure of private financial information.
Technical details
A vulnerability in the Configuration component of Oracle Banking Origination (version 14.5.0.16.0) allows an unauthenticated attacker with network access via HTTP to compromise the application. The exploit requires human interaction from a person other than the attacker (UI:R) and results in a scope change (S:C), suggesting a Cross-Site Scripting (XSS) or similar injection-based attack. Successful exploitation can result in unauthorized read access to a subset of data as well as unauthorized update, insert, or delete access to some accessible data. The vulnerability is tracked as part of the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Banking Origination 14.5.0.16.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published