Junglewise Threat Intelligence

CVE-2026-61280: Oracle Sales for Handhelds data manipulation in Outlook Sync Win 32

CVE-2026-61280 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in the Outlook Sync component of Oracle Sales for Handhelds, a tool used by mobile sales teams to synchronize data with Microsoft Outlook. An attacker with basic user credentials could exploit this flaw over the network to view, modify, or delete sensitive sales data. Additionally, the exploit can be used to disrupt the service, potentially impacting business operations and data integrity.

Technical details

This vulnerability affects the Outlook Sync Win 32 component of Oracle Sales for Handhelds within Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation enables unauthorized read, update, insert, or delete access to a subset of accessible data. Furthermore, an attacker can trigger a partial denial of service (DoS). The vulnerability has a CVSS 3.1 base score of 6.3, reflecting impacts on confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle Sales for Handhelds (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References