Junglewise Threat Intelligence

CVE-2026-62514: Oracle E-Business Suite data compromise in Process Manufacturing Regulatory Management

CVE-2026-62514 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle E-Business Suite, a widely used enterprise resource planning (ERP) platform, contains a vulnerability in its manufacturing regulatory management component. An attacker with basic user credentials can gain unauthorized access to sensitive business data, including the ability to modify or delete critical records. This could lead to significant data integrity issues and the exposure of proprietary manufacturing or regulatory information.

Technical details

A vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Regulatory Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows for unauthorized creation, deletion, or modification of critical data, as well as complete read access to all data accessible by the component. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high confidentiality and integrity impacts without affecting availability. Users should refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle E-Business Suite (Process Manufacturing Regulatory Management) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: NVD publication date

References

Related threats