Junglewise Threat Intelligence

CVE-2026-61329: Oracle Price Protection data manipulation in Oracle E-Business Suite

CVE-2026-61329 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Price Protection. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability in the Internal Operations component of Oracle Price Protection could allow an authorized user with low-level permissions to gain full access to sensitive pricing data. An attacker could view, modify, or delete critical business information, potentially leading to financial inaccuracies or unauthorized price changes. This issue affects organizations using Oracle E-Business Suite versions 12.2.3 through 12.2.15.

Technical details

This vulnerability affects the Internal Operations component of Oracle Price Protection within Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation grants unauthorized creation, deletion, or modification access to all accessible data within the Price Protection module, as well as full read access to critical data. The vulnerability has a CVSS 3.1 base score of 8.1, impacting both confidentiality and integrity, though it does not impact service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Price Protection (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published.

References

Related threats