Description
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Call Back). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iSupport accessible data as well as unauthorized read access to a subset of Oracle iSupport accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle iSupport product is affected by a vulnerability in the Call Back component, which allows a low‑privileged attacker to obtain unauthorized read, insert, update, or delete access to some internal data. The weakness stems from improper authorization checks, leading to permission escalation and potential loss of confidentiality and integrity for the affected data.

Affected Systems

Affects Oracle E‑Business Suite versions 12.2.3 through 12.2.15 of Oracle iSupport. The vulnerability is present in the Call Back component. All installations of these versions exposed over HTTP are susceptible.

Risk and Exploitability

The CVSS 3.1 base score of 5.4 signals a moderate severity. The EPSS score is below 1%, indicating a low probability of widespread exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Attacks can be carried out over the network via HTTP by users with limited privileges, without user interaction. The impact is limited to confidentiality and integrity of selected data, with no denial‑of‑service effect.

Generated by OpenCVE AI on August 4, 2026 at 01:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle iSupport patch or update that addresses CVE‑2026‑61257.
  • Restrict HTTP access to Oracle iSupport to trusted internal networks or IP ranges.
  • Enforce least privilege for users interacting with Oracle iSupport and review permission levels to ensure only essential rights.
  • Monitor Oracle iSupport logs for signs of unauthorized data access attempts.

Generated by OpenCVE AI on August 4, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege HTTP Access in Oracle iSupport

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege HTTP Access in Oracle iSupport

Mon, 27 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle iSupport via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle iSupport via HTTP

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Call Back). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iSupport accessible data as well as unauthorized read access to a subset of Oracle iSupport accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle isupport
CPEs cpe:2.3:a:oracle:isupport:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle isupport
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:24:58.103Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61257

cve-icon Vulnrichment

Updated: 2026-07-22T15:24:41.185Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses