Vulnerability in Oracle Advanced Benefits of Oracle E-Business Suite
CVE-2026-61325

7.6HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-61325?

A vulnerability exists in the Oracle Advanced Benefits component of Oracle E-Business Suite, specifically affecting version 12.2.15. This flaw can be easily exploited by high-privileged attackers with network access through HTTP. If successfully exploited, this vulnerability can lead to unauthorized access to sensitive data, granting attackers the ability to view, update, insert, or delete data within the Oracle Advanced Benefits system. The implications of this vulnerability extend beyond just Oracle Advanced Benefits, potentially impacting additional products within the suite.

Affected Version(s)

Oracle Advanced Benefits 12.2.15

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.