Executive brief
A vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Logistics, a tool used by businesses to manage manufacturing supply chains and logistics. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could lead to the theft of proprietary information or the unauthorized modification and deletion of critical logistics records.
Technical details
An unspecified vulnerability in the Internal Operations component of Oracle Process Manufacturing Logistics (versions 12.2.3 through 12.2.15) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation can result in unauthorized read access to all accessible data (High Confidentiality impact) and unauthorized update, insert, or delete access to a subset of data (Low Integrity impact). The vulnerability does not require user interaction and has no impact on service availability.
Affected products
- Oracle Corporation Oracle Process Manufacturing Logistics 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: CVE-2026-61299 was published to the NVD.