Junglewise Threat Intelligence

CVE-2026-61304: Oracle Price Protection data manipulation in Internal Operations

CVE-2026-61304 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle Price Protection. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Price Protection, a tool used by businesses to manage price changes and protect profit margins. An authorized user with low-level permissions could exploit this flaw to view, modify, or delete sensitive pricing data. Additionally, an attacker could disrupt the service, potentially impacting financial operations and data integrity.

Technical details

This vulnerability affects the Internal Operations component of Oracle Price Protection within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that can be triggered over the network via HTTP. An attacker requires low-level authentication (PR:L) to successfully exploit the vulnerability. Impact includes unauthorized read access to a subset of data, unauthorized update/insert/delete capabilities for certain records, and the ability to cause a partial denial of service (DoS). The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle Price Protection (Oracle E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats