Vulnerability in Oracle E-Business Suite's Production Scheduling Component
CVE-2026-61046

6.6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-61046?

An improper access control vulnerability exists in the Oracle E-Business Suite's Production Scheduling component, allowing high-privileged attackers with network access via HTTP to exploit the system. This vulnerability permits unauthorized creation, deletion, or modification of critical data, affecting the integrity and confidentiality of all accessible data. In addition, it may enable unauthorized read access to a portion of the data managed by Oracle Production Scheduling, thereby posing a serious risk to organizational data security.

Affected Version(s)

Oracle Production Scheduling 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.