Executive brief
Oracle E-Business Suite, a comprehensive suite of business applications, contains a vulnerability in its U.S. Federal Financials module. An attacker with basic user credentials can gain unauthorized access to sensitive financial data over the network. This could lead to the exposure of internal government or organizational financial records.
Technical details
A vulnerability in the Internal Operations component of Oracle U.S. Federal Financials (part of Oracle E-Business Suite) allows for unauthorized read access to data. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation results in a loss of confidentiality for a subset of data within the module. The issue affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation E-Business Suite (Oracle U.S. Federal Financials) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-61292 by Oracle.