Junglewise Threat Intelligence

CVE-2026-62479: Oracle Public Sector Financials data compromise in Internal Operations

CVE-2026-62479 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Public Sector Financials. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Public Sector Financials, a suite used by government organizations to manage accounting and budgeting. An attacker with low-level access could trick a legitimate user into performing actions that allow the attacker to view, modify, or delete sensitive financial data. While the flaw is within the financials module, a successful exploit could potentially impact other connected business systems.

Technical details

This vulnerability affects the Internal Operations component of Oracle Public Sector Financials (versions 12.2.3 through 12.2.15). It is classified as a cross-site style vulnerability requiring human interaction (UI:R) and a scope change (S:C), meaning an exploit can impact resources beyond the immediate security scope of the component. An attacker with low-privileged network access via HTTP can perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of the application's data. The vulnerability is easily exploitable provided a legitimate user interacts with the malicious request. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle Public Sector Financials (E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: advisory: Initial publication by Oracle and NVD

References

Related threats