Junglewise Threat Intelligence

CVE-2026-61266: Oracle E-Business Suite data manipulation in Supply Chain Globalization

CVE-2026-61266 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Oracle E-Business Suite component used for managing global supply chain inventory. An attacker with basic user credentials could remotely access, modify, or delete certain supply chain data, potentially disrupting logistics operations or compromising inventory records. This could lead to inaccurate stock levels or temporary unavailability of the management interface.

Technical details

This vulnerability affects the 'Copy Inventory Organization' component within Oracle Supply Chain Globalization (part of Oracle E-Business Suite). It is classified as an easily exploitable flaw that requires network access via HTTP and low-level user privileges. An attacker can successfully exploit this to gain unauthorized read, update, insert, or delete access to a subset of the application's data. Additionally, the exploit can result in a partial denial of service (DoS) affecting the availability of the component. The affected versions range from 12.2.3 through 12.2.15.

Affected products

  • Oracle Corporation E-Business Suite Supply Chain Globalization 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-61266
  • 2026-07-21: advisory: Oracle Critical Patch Update (CPU) July 2026 released

References