Junglewise Threat Intelligence

CVE-2026-61283: Oracle Bills of Material unauthorized data access in Web Services

CVE-2026-61283 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle Bills of Material. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Web Services component of Oracle Bills of Material, a module within the Oracle E-Business Suite used for managing manufacturing product structures. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive manufacturing data. Additionally, an exploit could disrupt operations by causing a partial denial of service, potentially impacting production planning and inventory management.

Technical details

This vulnerability affects the Web Services component of Oracle Bills of Material within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can achieve unauthorized read, update, insert, or delete access to a subset of data within the Bills of Material module. Furthermore, the exploit can result in a partial denial of service (DoS). The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Bills of Material 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update (CPU) published

References

Related threats