Junglewise Threat Intelligence

CVE-2026-62486: Oracle Contracts Integration unauthorized data access in Internal Operations

CVE-2026-62486 · Severity: medium · CVSS 5 · Published 2026-07-21

Technologies: Oracle Contracts Integration. Vendors: Oracle, Oracle Corporation.

Executive brief

A security vulnerability exists in the Oracle Contracts Integration component of the Oracle E-Business Suite, which is used by organizations to manage business contracts and internal operations. An attacker could potentially gain unauthorized access to view, modify, or delete sensitive contract data, or cause a partial disruption of the service. Exploiting this flaw is difficult as it requires a legitimate user to interact with a malicious link or site while the attacker targets the system over the network.

Technical details

A vulnerability in the Internal Operations component of Oracle Contracts Integration (Oracle E-Business Suite) allows an unauthenticated attacker with network access via HTTP to compromise the application. The vulnerability is characterized by high attack complexity and requires human interaction from a user other than the attacker (UI:R). Successful exploitation can result in unauthorized read, update, insert, or delete access to a subset of accessible data, as well as a partial denial of service. Affected versions include 12.2.3 through 12.2.15. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Oracle Contracts Integration 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed: CVE-2026-62486 was published to the NVD.

References

Related threats