Description
Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration). The supported version that is affected is 14.5.0.16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Origination, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as unauthorized read access to a subset of Oracle Banking Origination accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the configuration component of Oracle Banking Origination lets an attacker who can reach the system through HTTP bypass permission checks and make unauthorized updates, inserts, or deletions of data, and read restricted information. The vulnerability is an access‑control bypass (CWE‑284) that can compromise the confidentiality and integrity of data accessed by the application. Successful exploitation also requires human interaction from a user other than the attacker, which reduces the likelihood of a purely automated attack.

Affected Systems

Oracle Banking Origination version 14.5.0.16.0 is affected. The description notes that exploitation of this flaw may also have implications for other products within the Oracle Financial Services Applications suite, but no other products are explicitly listed.

Risk and Exploitability

The CVSS base score of 6.1 classifies the flaw as moderate severity, and the EPSS score of less than 1 % indicates a low but non‑zero likelihood of exploitation. The attack vector is network-based via HTTP, requires no authentication, but also requires user interaction with a non‑attacker to complete the exploit. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known public exploitation.

Generated by OpenCVE AI on August 4, 2026 at 16:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch for Oracle Banking Origination version 14.5.0.16.0 as noted in the Oracle CPU July 2026 advisory.
  • Restrict HTTP access to the Oracle Banking Origination servers with a firewall or network segmentation, exposing the configuration interface only to trusted administrators.
  • Enforce strong authentication and role‑based access controls on the configuration API to prevent unauthorized write operations.
  • Monitor application logs for configuration API usage and for anomalous data modification events.

Generated by OpenCVE AI on August 4, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification and Disclosure

Sun, 02 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification and Disclosure

Sat, 01 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unrestricted Configuration Access in Oracle Banking Origination Leads to Unauthorized Data Tampering

Mon, 27 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unrestricted Configuration Access in Oracle Banking Origination Leads to Unauthorized Data Tampering

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration). The supported version that is affected is 14.5.0.16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Origination, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as unauthorized read access to a subset of Oracle Banking Origination accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle banking Origination
CPEs cpe:2.3:a:oracle:banking_origination:14.5.0.16.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle banking Origination
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Banking Origination
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:19:45.425Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61220

cve-icon Vulnrichment

Updated: 2026-07-22T18:19:41.893Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses