Junglewise Threat Intelligence

CVE-2026-62490: Oracle Contracts Integration Information Disclosure in Internal Operations

CVE-2026-62490 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle Contracts Integration. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Contracts Integration, a module within the Oracle E-Business Suite used for managing business agreements. An attacker with basic user credentials could exploit this flaw to gain unauthorized access to sensitive contract data. This could lead to the exposure of confidential business terms, financial details, or proprietary information stored within the system.

Technical details

This vulnerability affects the Internal Operations component of Oracle Contracts Integration within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a confidentiality-impacting bug that allows a low-privileged attacker to gain unauthorized access to sensitive data. The attack vector is network-based via HTTP, though the exploit is characterized as having high complexity (AC:H), suggesting specific environmental conditions or timing may be required. Successful exploitation results in the unauthorized disclosure of critical data or complete access to all data accessible by the Contracts Integration module. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Contracts Integration 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats