Unauthenticated Access Vulnerability in Oracle E-Business Suite's Maintenance, Repair and Overhaul
CVE-2026-61138

7.5HIGH

What is CVE-2026-61138?

An unauthenticated access vulnerability exists in the Oracle Complex Maintenance, Repair and Overhaul product within Oracle E-Business Suite. This vulnerability allows an attacker with network access via HTTP to potentially compromise the system. While primarily affecting the maintenance and overhaul component, successful exploitation could lead to unauthorized access to critical data. Attackers may also gain the ability to update, insert, or delete accessible data, causing significant security implications for the ecosystem. Immediate action is recommended to safeguard sensitive information.

Affected Version(s)

Oracle Complex Maintenance, Repair and Overhaul 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.