Junglewise Threat Intelligence

CVE-2026-61309: Oracle In-Memory Cost Management unauthorized data access in Internal Operations

CVE-2026-61309 · Severity: high · CVSS 7.5 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle In-Memory Cost Management, a tool used by manufacturing businesses to analyze and manage production costs within the Oracle E-Business Suite. An unauthorized person could use this flaw over the network to gain access to sensitive financial and operational data. This could lead to the exposure of proprietary cost structures or critical business information without requiring any user interaction.

Technical details

A vulnerability in the Internal Operations component of Oracle In-Memory Cost Management for Discrete Industries (part of Oracle E-Business Suite) allows for unauthorized data access. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation results in a high confidentiality impact, potentially allowing the attacker to access all data within the affected component. Affected versions range from 12.2.3 through 12.2.15. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle In-Memory Cost Management for Discrete Industries 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats