Junglewise Threat Intelligence

CVE-2026-61294: Oracle Common Applications Calendar data manipulation in Calendar Synchronizations

CVE-2026-61294 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle E-Business Suite's calendar synchronization component contains a vulnerability that allows an authorized user to interfere with calendar data. An attacker with basic login credentials could view, modify, or delete certain calendar entries and cause minor service disruptions. This could lead to unauthorized access to scheduling information or the corruption of organizational calendar data.

Technical details

A vulnerability exists in the Calendar Synchronizations component of Oracle Common Applications Calendar (part of Oracle E-Business Suite). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows an attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of accessible calendar data. Additionally, the attacker can trigger a partial denial of service (DoS) affecting the component's availability. The vulnerability affects versions 12.2.3 through 12.2.15.

Affected products

  • Oracle Common Applications Calendar 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References