Junglewise Threat Intelligence

CVE-2026-61310: Oracle Product Hub data compromise in Internal Operations

CVE-2026-61310 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Product Hub. Vendors: Oracle, Oracle Corporation.

Executive brief

Oracle Product Hub, a component of the Oracle E-Business Suite used for managing centralized product information, contains a security vulnerability in its Internal Operations component. An attacker with basic user credentials can exploit this flaw over the network to gain full access to sensitive product data. This could lead to the unauthorized viewing, modification, or deletion of critical business information, potentially disrupting supply chain operations and compromising proprietary data.

Technical details

This vulnerability exists in the Internal Operations component of Oracle Product Hub (part of Oracle E-Business Suite). It is classified as an easily exploitable flaw that requires low-privileged authentication and can be triggered over the network via HTTP. A successful exploit allows an attacker to bypass intended access controls to achieve high confidentiality and integrity impacts, specifically the unauthorized creation, deletion, or modification of all data accessible within the Product Hub. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to consult the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Product Hub 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats