Executive brief
A vulnerability exists in Oracle Call Center Technology, a component of the Oracle E-Business Suite used for managing customer interactions and contact center operations. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive call center data. This could lead to unauthorized changes in customer records or the exposure of private business information.
Technical details
This vulnerability affects the RDBMS and UI components of Oracle Call Center Technology within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an improper access control or data validation issue that allows a low-privileged attacker to perform unauthorized actions via HTTP. The attack vector is network-based and requires no user interaction, though the attacker must be authenticated with at least low-level privileges. Successful exploitation grants the attacker the ability to read, insert, update, or delete a subset of data managed by the Call Center Technology module. The vulnerability was addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Corporation Oracle Call Center Technology (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-61264 was published to the NVD.