Junglewise Threat Intelligence

CVE-2026-62474: Oracle Lease and Finance Management unauthorized data access in Lease Authoring

CVE-2026-62474 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle Lease and Finance Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the Lease Authoring component of Oracle Lease and Finance Management, a tool used by businesses to manage equipment leasing and financial contracts. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive financial data. Additionally, an exploit could disrupt business operations by causing a partial service outage.

Technical details

This vulnerability affects the Lease Authoring component of Oracle Lease and Finance Management (part of Oracle E-Business Suite). It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. Successful exploitation allows an attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of the application's data. Furthermore, the vulnerability can be leveraged to cause a partial denial of service (DoS), impacting the availability of the Lease Authoring module. The issue affects versions 12.2.3 through 12.2.15 and was addressed in the July 2026 Oracle Critical Patch Update.

Affected products

  • Oracle Lease and Finance Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats