Junglewise Threat Intelligence

CVE-2026-61261: Oracle Knowledge Management unauthorized data access in User Interface

CVE-2026-61261 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Knowledge Management. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the User Interface component of Oracle Knowledge Management, a tool within the Oracle E-Business Suite used for managing organizational information and documentation. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain data within the system. This could lead to unauthorized changes to corporate knowledge bases or the exposure of sensitive internal information.

Technical details

This vulnerability affects the User Interface component of Oracle Knowledge Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an improper access control or data validation issue that allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation enables the attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of the data accessible to the Knowledge Management module. The attack does not require user interaction and has a low complexity, though it does require valid low-level authentication credentials. The fix is included in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Knowledge Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed

References

Related threats