Description
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Affordable Care Act). Supported versions that are affected are 12.2.7-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Benefits. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker who can access the Oracle Advanced Benefits application over HTTP can exploit an access control weakness in the Affordable Care Act component. The flaw, identified as CWE‑269, CWE‑284, and CWE‑306, allows an attacker to bypass authentication and access privileged functionality, thereby compromising the application’s confidentiality, integrity, and availability. Successful exploitation therefore permits a complete takeover of the product. The weakness carries a CVSS v3.1 base score of 7.5, reflecting moderate to severe risk, though the description notes difficulty in exploitation.

Affected Systems

Oracle Advanced Benefits versions 12.2.7 through 12.2.15 are affected. The product is part of the Oracle E‑Business Suite and is deployed by organizations that use the Affordable Care Act module.

Risk and Exploitability

The CVSS base score of 7.5 coupled with an EPSS score of less than 1 % indicates that while the potential impact is high, the likelihood of active exploitation is low. The vulnerability can be leveraged by an attacker who has network access to the web interface and holds a low‑privilege account; no user interaction is required. Once the condition is met, exploitation results in a complete takeover of the application. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 5, 2026 at 01:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU patch for CVE‑2026‑61141 as disclosed in the Oracle security alert.
  • Restrict inbound HTTP access to the Advanced Benefits instance to trusted IP ranges or VPN endpoints.
  • Enforce least privilege on all service accounts that communicate with Advanced Benefits.

Generated by OpenCVE AI on August 5, 2026 at 01:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Takeover of Oracle Advanced Benefits

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Takeover of Oracle Advanced Benefits

Thu, 30 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Full Takeover of Oracle Advanced Benefits

Mon, 27 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Full Takeover of Oracle Advanced Benefits

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Affordable Care Act). Supported versions that are affected are 12.2.7-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Benefits. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle advanced Benefits
CPEs cpe:2.3:a:oracle:advanced_benefits:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Benefits
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Advanced Benefits
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:57:16.909Z

Reserved: 2026-07-08T15:51:55.616Z

Link: CVE-2026-61141

cve-icon Vulnrichment

Updated: 2026-07-23T18:53:03.790Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function