Unauthenticated Access Vulnerability in Oracle E-Business Suite's Production Scheduling by Oracle
CVE-2026-61049

7.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-61049?

A vulnerability in the Oracle E-Business Suite's Production Scheduling component allows an unauthenticated attacker with access to the local physical communication segment to compromise the system. Although the exploitation of this vulnerability requires human interaction from a third party, successful attacks could lead to unauthorized control of the Production Scheduling system. This can significantly impact the integrity, confidentiality, and availability of the organization's data and operations.

Affected Version(s)

Oracle Production Scheduling 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.