Description
Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Servers). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Inbound Telephony accessible data as well as unauthorized read access to a subset of Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an access‑control flaw (CWE‑284) in the Oracle Advanced Inbound Telephony component of Oracle E‑Business Suite. The flaw allows an attacker who has a low‑privileged account with network reach to the HTTP interface to perform unauthorized updates, inserts, or deletes, read portions of protected data, and trigger a partial denial of service. These capabilities lead to breaches of confidentiality, integrity, and availability for the affected Telephony data.

Affected Systems

Affected systems are Oracle Advanced Inbound Telephony deployments running Oracle E‑Business Suite versions 12.2.3, 12.2.4, up to and including 12.2.15. Other versions outside this range are not listed as vulnerable. The issue resides in the server component accessed via HTTP.

Risk and Exploitability

The CVSS v3.1 base score of 6.3 signals moderate severity, while an EPSS score of less than 1 % indicates a very low likelihood of real‑world exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the flaw over the network through the public or internal HTTP endpoint and only need a low‑privilege account, so the attack vector is remote. Although exploitation probability is low, the potential for unauthorized data manipulation warrants immediate remediation.

Generated by OpenCVE AI on August 4, 2026 at 01:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle E‑Business Suite patch that contains the fix for CVE‑2026‑61256
  • Restrict HTTP access to the Advanced Inbound Telephony service to trusted networks or a VPN to reduce exposure
  • Monitor logs and data integrity for signs of unauthorized modifications or partial service outages

Generated by OpenCVE AI on August 4, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Access Control Weakness in Oracle Advanced Inbound Telephony Enables Unauthorized Data Modification and Partial Denial of Service

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Access Control Weakness in Oracle Advanced Inbound Telephony Enables Unauthorized Data Modification and Partial Denial of Service

Mon, 27 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Access Allows Data Modification and Partial Denial of Service in Oracle Advanced Inbound Telephony

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Access Allows Data Modification and Partial Denial of Service in Oracle Advanced Inbound Telephony

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Servers). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Inbound Telephony accessible data as well as unauthorized read access to a subset of Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle advanced Inbound Telephony
CPEs cpe:2.3:a:oracle:advanced_inbound_telephony:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Inbound Telephony
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Advanced Inbound Telephony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:26:43.011Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61256

cve-icon Vulnrichment

Updated: 2026-07-22T15:26:38.542Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses