Junglewise Threat Intelligence

CVE-2026-61338: Oracle Contracts Integration data compromise in Internal Operations

CVE-2026-61338 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Contracts Integration. Vendors: Oracle, Oracle Corporation.

Executive brief

Oracle Contracts Integration, a component of the Oracle E-Business Suite used for managing business agreements, contains a security vulnerability in its Internal Operations module. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive contract data. This could result in the theft, deletion, or modification of critical business records, potentially disrupting legal and financial operations.

Technical details

This vulnerability exists in the Internal Operations component of Oracle Contracts Integration (part of Oracle E-Business Suite). It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system without user interaction. The exploit enables unauthorized creation, deletion, or modification of data, as well as complete unauthorized access to all data accessible by the component. The vulnerability affects versions 12.2.3 through 12.2.15. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation Oracle Contracts Integration 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed: CVE-2026-61338 was published to the NVD.

References

Related threats