Executive brief
A vulnerability exists in the Attachments component of Oracle's Document Management and Collaboration tool, which is part of the E-Business Suite used by organizations to manage and share corporate documents. An unauthorized person could use the internet to access, change, or delete certain business data without needing a username or password. This could lead to the loss of sensitive information, unauthorized modification of records, or temporary disruptions to the document management service.
Technical details
This vulnerability affects the Attachments component of Oracle Document Management and Collaboration within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation enables an attacker to perform unauthorized updates, insertions, or deletions of data, as well as unauthorized read access to a subset of accessible data. Additionally, the vulnerability can be used to cause a partial denial of service (DoS). The CVSS 3.1 base score is 7.3, reflecting impacts on confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.
Affected products
- Oracle Document Management and Collaboration 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-61271
- 2026-07-21: advisory: Oracle released security alert cpujul2026.html