Junglewise Threat Intelligence

CVE-2026-61328: Oracle Cost Management compromise in Cost Planning

CVE-2026-61328 · Severity: medium · CVSS 6.6 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in Oracle Cost Management, a tool used by businesses to track and analyze manufacturing and inventory costs within the Oracle E-Business Suite. A highly privileged attacker could exploit this flaw to gain full control over the Cost Management component. While the attack is difficult to perform and requires existing high-level access, a successful breach could lead to the unauthorized modification or theft of sensitive financial and operational data.

Technical details

This vulnerability affects the Cost Planning component of Oracle Cost Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a difficult-to-exploit flaw that requires the attacker to already possess high-level privileges (PR:H). The attack vector is remote via HTTP (AV:N), but high complexity (AC:H) suggests specific environmental conditions or timing are required for success. If successfully exploited, the attacker can achieve a complete compromise of the component, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle Cost Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed: CVE-2026-61328 was published to the NVD.

References