Vulnerability in Oracle E-Business Suite Maintenance Product
CVE-2026-61306

7.1HIGH

What is CVE-2026-61306?

A security flaw exists in the Oracle Complex Maintenance, Repair and Overhaul component of the Oracle E-Business Suite, impacting multiple supported versions. An attacker with limited privileges and HTTP network access can exploit this vulnerability to gain unauthorized access to sensitive data. The attacks may not only affect the vulnerable component but could also have broader implications on additional related products. Successful exploitation allows unauthorized users to access critical data and poses a risk of causing a partial denial of service, ultimately compromising the integrity and availability of the Oracle E-Business Suite maintenance functionalities.

Affected Version(s)

Oracle Complex Maintenance, Repair and Overhaul 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.