Junglewise Threat Intelligence

CVE-2026-61221: Oracle Item Master unauthorized data access in iSet-up

CVE-2026-61221 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Item Master component of the Oracle E-Business Suite, which is used by organizations to manage product data and inventory definitions. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain sensitive business data. This could lead to unauthorized changes in inventory records or the exposure of proprietary product information.

Technical details

A vulnerability in the iSet-up component of Oracle Item Master (Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to read a subset of accessible data and perform unauthorized updates, inserts, or deletions of records within the Item Master. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Item Master 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References