Description
Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Interaction Blending executes to compromise Oracle Interaction Blending. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Interaction Blending accessible data as well as unauthorized access to critical data or complete access to all Oracle Interaction Blending accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control in Oracle Interaction Blending enables a low‑privileged local attacker—one who has logged into the underlying system—to create, delete, or modify critical data. The flaw permits the attacker to gain complete read access to all data the component handles, breaching confidentiality and integrity. The weakness is identified as CWE‑284, a permission or access control issue.

Affected Systems

Oracle Interaction Blending, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15 in the Internal Operations module. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 indicates a medium‑high risk. Exploitation requires local access with low privileges and no user interaction; the attack vector is local. The EPSS score is below 1%, implying a very low probability of current exploitation, and the vulnerability is not recorded in the CISA KEV catalogue. Attackers must first obtain on‑premises access to the host running Interaction Blending, then exploit the access‑control flaw to perform data‑manipulation operations.

Generated by OpenCVE AI on August 4, 2026 at 03:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Security Patch for Interaction Blending released in the July 2026 alert
  • Enforce least‑privilege on local accounts that can log onto Interaction Blending hosts, disabling unnecessary user accounts
  • Configure comprehensive auditing for data modification events and regularly review audit logs
  • If patch deployment is delayed, isolate Interaction Blending servers from the broader network and restrict direct local logon rights to trusted administrators

Generated by OpenCVE AI on August 4, 2026 at 03:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Insufficient Access Control in Oracle Interaction Blending Allows Local Attacker to Modify Critical Data

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Insufficient Access Control in Oracle Interaction Blending Allows Local Attacker to Modify Critical Data

Mon, 27 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Interaction Blending Leading to Unauthorized Data Modification

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Interaction Blending Leading to Unauthorized Data Modification
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Interaction Blending executes to compromise Oracle Interaction Blending. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Interaction Blending accessible data as well as unauthorized access to critical data or complete access to all Oracle Interaction Blending accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle interaction Blending
CPEs cpe:2.3:a:oracle:interaction_blending:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle interaction Blending
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Interaction Blending
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:24:30.797Z

Reserved: 2026-07-08T15:51:55.580Z

Link: CVE-2026-60703

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:45.449Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:10.713

Modified: 2026-08-07T21:03:03.220

Link: CVE-2026-60703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses