Vulnerability in Oracle Advanced Benefits of Oracle E-Business Suite
CVE-2026-61324

7.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-61324?

A vulnerability in the Oracle Advanced Benefits product, part of the Oracle E-Business Suite, allows low privileged attackers with network access via HTTP to compromise the application. This weakness can lead to unauthorized creation, deletion, or modification of critical data, potentially impacting additional products within the suite. The issue is present in version 12.2.15, necessitating immediate attention to secure sensitive data against exploitation.

Affected Version(s)

Oracle Advanced Benefits 12.2.15

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.