Description
Vulnerability in the Oracle Item Master product of Oracle E-Business Suite (component: iSet-up bugs). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Item Master. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Item Master accessible data as well as unauthorized read access to a subset of Oracle Item Master accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This access‑control weakness in Oracle Item Master, affecting versions 12.2.3 through 12.2.15, enables a low‑privileged attacker who can reach the application via HTTP to create, modify, or delete items, and to read a subset of the data. The vulnerability is a CWE‑284 flaw that subverts normal permissions and compromises both confidentiality and integrity of the company’s item master records.

Affected Systems

Oracle Corporation’s Item Master product is the only vendor/product impacted by this CVE. Systems running any of the Oracle Item Master releases from 12.2.3 to 12.2.15 are vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 5.4 indicates moderate severity, reflecting low confidentiality and integrity impact but requiring no authentication. The EPSS score of less than 1% suggests that exploitation is currently considered rare, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the lack of an authentication barrier, coupled with the ability to inject, modify, or delete records, means that a low‑privileged attacker with network access can permanently alter critical business data. Monitoring and prompt remediation are recommended.

Generated by OpenCVE AI on August 4, 2026 at 01:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Item Master update that addresses CVE-2026-61221.
  • Limit Item Master write privileges to a restricted set of roles, ensuring that only authorized users have create, update, or delete capabilities.
  • Configure network or application firewalls to restrict HTTP access to the Item Master service to trusted hosts or IP ranges, thereby reducing the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Item Master via HTTP

Sun, 02 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Oracle Item Master Enables Unauthorized Data Modification via HTTP

Mon, 27 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Oracle Item Master Enables Unauthorized Data Modification via HTTP

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Item Master product of Oracle E-Business Suite (component: iSet-up bugs). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Item Master. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Item Master accessible data as well as unauthorized read access to a subset of Oracle Item Master accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle item Master
CPEs cpe:2.3:a:oracle:item_master:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle item Master
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Item Master
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:24:54.052Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61221

cve-icon Vulnrichment

Updated: 2026-07-22T18:24:46.966Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses