Junglewise Threat Intelligence

CVE-2026-61335: Oracle E-Business Suite Product Workbench data compromise in Internal Operations

CVE-2026-61335 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Product Workbench. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Product Workbench, a tool used within the Oracle E-Business Suite for managing product lifecycles and data. An attacker with basic user credentials can exploit this flaw over the network to gain full access to sensitive business data. This could lead to the unauthorized viewing, modification, or deletion of critical product information, potentially disrupting supply chain operations or compromising proprietary designs.

Technical details

This vulnerability affects the Internal Operations component of Oracle Product Workbench within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can leverage this vulnerability to achieve high confidentiality and integrity impacts, specifically allowing for the unauthorized creation, deletion, or modification of all data accessible to the Product Workbench. The attack does not require user interaction and has no impact on system availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Product Workbench (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-61335 by Oracle

References

Related threats