Junglewise Threat Intelligence

CVE-2026-61274: Oracle Product Hub unauthorized data access in Item Catalog

CVE-2026-61274 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle Product Hub. Vendors: Oracle, Oracle Corporation.

Executive brief

Oracle Product Hub, a component of the Oracle E-Business Suite used for managing centralized product information, contains a security vulnerability. An attacker with low-level user credentials can exploit this flaw over the network to view, modify, or delete certain product data. Additionally, an exploit could cause a partial service disruption, impacting the availability of the product catalog for other users.

Technical details

A vulnerability exists in the Item Catalog component of Oracle Product Hub (versions 12.2.3 through 12.2.15). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows for unauthorized read, update, insert, or delete access to a subset of data within the Product Hub. Furthermore, the vulnerability can be leveraged to cause a partial denial of service (DoS). The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Product Hub (Item Catalog) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats