Vulnerability in Oracle E-Business Suite's Affordable Care Act Component
CVE-2026-61141

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-61141?

This vulnerability in Oracle Advanced Benefits allows an attacker with low-level privileges and network access to compromise the application through HTTP. It could enable unauthorized access, resulting in the potential takeover of the affected component, which could have serious implications for confidentiality, integrity, and availability of sensitive data.

Affected Version(s)

Oracle Advanced Benefits 12.2.7 <= 12.2.15

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.