Junglewise Threat Intelligence

CVE-2026-61279: Oracle E-Business Suite unauthorized data access in Proposals

CVE-2026-61279 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Vendors: Oracle, Oracle Corporation.

Executive brief

Oracle Proposals, a component of the Oracle E-Business Suite used for managing business proposals and sales documents, contains a security vulnerability. An attacker with low-level user credentials can exploit this flaw over the network to view, modify, or delete certain business data. Additionally, an exploit could cause a partial service outage, disrupting normal business operations.

Technical details

A vulnerability in the Proposals component of Oracle E-Business Suite (versions 12.2.3 through 12.2.15) allows for unauthorized access and modification of data. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation can result in unauthorized read, update, insert, or delete access to a subset of Oracle Proposals data. It also allows an attacker to cause a partial denial of service (DoS). The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Proposals 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed

References