Junglewise Threat Intelligence

CVE-2026-62480: Oracle Public Sector Financials information disclosure in Internal Operations

CVE-2026-62480 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Public Sector Financials. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Public Sector Financials, a component of the Oracle E-Business Suite used by government organizations to manage accounting and budgeting. An attacker with basic user access to the network can exploit this flaw to view sensitive financial data. This could lead to the unauthorized exposure of critical government financial records or internal operational data.

Technical details

An information disclosure vulnerability exists in the Internal Operations component of Oracle Public Sector Financials (part of Oracle E-Business Suite). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended confidentiality restrictions, resulting in unauthorized access to critical data or complete access to all data accessible through the Public Sector Financials module. The vulnerability affects versions 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.

Affected products

  • Oracle Public Sector Financials 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats