Junglewise Threat Intelligence

CVE-2026-62478: Oracle Public Sector Financials takeover in Internal Operations

CVE-2026-62478 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Public Sector Financials. Vendors: Oracle.

Executive brief

Oracle Public Sector Financials, a component of the Oracle E-Business Suite used by government entities to manage accounting and budgeting, contains a critical security vulnerability. An attacker with basic user access to the network can exploit this flaw to take full control of the financial system. This could lead to the unauthorized disclosure of sensitive financial data, manipulation of records, or a total disruption of financial operations.

Technical details

A vulnerability exists in the Internal Operations component of Oracle Public Sector Financials (part of Oracle E-Business Suite). The flaw is easily exploitable via the HTTP protocol by a low-privileged attacker with network access to the application. Successful exploitation allows for a complete takeover of the affected product, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Public Sector Financials 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats