Junglewise Threat Intelligence

CVE-2026-62515: Oracle Advanced Planning Command Center unauthorized data access in Internal Operations

CVE-2026-62515 · Severity: high · CVSS 7.6 · Published 2026-07-21

Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Oracle Advanced Planning Command Center, a tool used within the Oracle E-Business Suite for supply chain planning and analytics. A high-privileged attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Because the vulnerability allows for a 'scope change,' an attack could potentially impact other integrated business systems beyond the planning center itself.

Technical details

This vulnerability affects the Internal Operations component of Oracle Advanced Planning Command Center (versions 12.2.3 through 12.2.15). It is classified as easily exploitable via the HTTP protocol, though it requires high-privileged administrative credentials (PR:H). The exploit results in a scope change (S:C), meaning a successful attack can impact resources beyond the immediate security scope of the affected component. Attackers can achieve full confidentiality impact (unauthorized access to all data) and partial integrity impact (unauthorized modification or deletion of some data). The vulnerability was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation Oracle Advanced Planning Command Center 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed

References