Junglewise Threat Intelligence

CVE-2026-61334: Oracle Price Protection unauthorized data modification in Internal Operations

CVE-2026-61334 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle Price Protection. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Price Protection, a tool used by businesses to manage price changes and protect profit margins. An attacker with basic user access can exploit this flaw over the network to modify, create, or delete critical business data. This could lead to significant financial inaccuracies, unauthorized pricing changes, and loss of data integrity within the enterprise resource planning system.

Technical details

This vulnerability affects the Internal Operations component of Oracle Price Protection within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of the application's data. The vulnerability has a CVSS 3.1 base score of 7.1, primarily impacting data integrity and confidentiality. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Price Protection (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-61334 via Oracle Critical Patch Update.

References

Related threats