Executive brief
A vulnerability exists in the Quality Management Specs component of Oracle Process Manufacturing Product Development, a tool used by manufacturers to manage product recipes and quality standards. An attacker with basic user access to the corporate network can exploit this flaw to gain full control over the application. This could lead to the theft of proprietary manufacturing data, unauthorized changes to product specifications, or a complete shutdown of the quality management system.
Technical details
A high-severity vulnerability exists in the Quality Management Specs component of Oracle Process Manufacturing Product Development (part of Oracle E-Business Suite). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the affected component, impacting confidentiality, integrity, and availability. The vulnerability affects version 12.2.15. While the specific CWE is not listed in the advisory, the impact indicates a significant authorization or injection-class flaw. Users should refer to the Oracle July 2026 Critical Patch Update for remediation steps.
Affected products
- Oracle Corporation Oracle Process Manufacturing Product Development 12.2.15
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-61289 by Oracle.
- 2026-07-21: advisory: NVD entry published.