Junglewise Threat Intelligence

CVE-2026-61316: Oracle EDI Gateway information disclosure in Oracle E-Business Suite

CVE-2026-61316 · Severity: medium · CVSS 4.3 · Published 2026-07-21

Technologies: Oracle EDI Gateway. Vendors: Oracle.

Executive brief

Oracle EDI Gateway, a component of the Oracle E-Business Suite used for electronic data interchange between business partners, contains a security vulnerability. An authorized user with low-level permissions can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could lead to the exposure of confidential transaction information or partner data.

Technical details

A vulnerability exists in the EDI component of Oracle EDI Gateway (Oracle E-Business Suite) versions 12.2.3 through 12.2.15. The flaw is categorized as easily exploitable and requires low-privileged authentication to execute. An attacker can leverage network access via HTTP to bypass intended access controls and perform unauthorized read operations on a subset of data accessible to the gateway. The vulnerability has a CVSS 3.1 base score of 4.3, primarily impacting data confidentiality. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.

Affected products

  • Oracle EDI Gateway 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats