Junglewise Threat Intelligence

CVE-2026-62483: Oracle Project Contracts unauthorized data manipulation in Internal Operations

CVE-2026-62483 · Severity: medium · CVSS 4.3 · Published 2026-07-21

Technologies: Oracle Project Contracts. Vendors: Oracle, Oracle Corporation.

Executive brief

Oracle Project Contracts, a component of the Oracle E-Business Suite used for managing contract lifecycles, contains a security vulnerability in its Internal Operations component. An attacker with basic user credentials can exploit this flaw over the network to modify, add, or delete certain contract-related data. While the attacker cannot steal sensitive information or shut down the system, they can compromise the integrity of business records.

Technical details

A vulnerability exists in the Internal Operations component of Oracle Project Contracts (part of Oracle E-Business Suite). The flaw is classified as easily exploitable and allows a low-privileged attacker with network access via HTTP to bypass certain integrity controls. Successful exploitation enables the attacker to perform unauthorized data manipulation, including updates, inserts, or deletes within the affected component's data scope. The vulnerability does not provide a path for data confidentiality breaches or service availability disruption. Affected versions range from 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle Corporation Oracle Project Contracts 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Initial publication by Oracle and NVD

References

Related threats