Description
Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: RDBMS and UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Call Center Technology accessible data as well as unauthorized read access to a subset of Oracle Call Center Technology accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper authorization controls in the RDBMS and UI components of Oracle Call Center Technology. It enables a low‑privileged attacker with network connectivity over HTTP to perform unauthorized updates, inserts, or deletions of accessible data and to read a subset of data that should be protected. The flaw results in confidentiality and integrity impacts on the application data.

Affected Systems

Oracle Call Center Technology, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. Only these releases are mentioned; earlier or later versions are not specified as vulnerable.

Risk and Exploitability

This risk has a CVSS 3.1 base score of 5.4, indicating moderate severity. EPSS is reported to be below 1%, suggesting a low likelihood of widespread exploitation, though the vulnerability is described as easily exploitable. The flaw is not listed in CISA’s KEV catalog and can be triggered by an attacker who has network access to the HTTP interfaces of the Call Center application. Being a low‑privileged access control issue, exploitation requires no special credentials, only HTTP connectivity to the affected server.

Generated by OpenCVE AI on August 4, 2026 at 01:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Call Center Technology update that addresses CVE-2026-61264.
  • Restrict HTTP access to the Call Center servers to internal networks or VPN only, limiting exposure to low‑privileged attackers.
  • Verify that role‑based access control enforces least‑privilege policies so that users cannot perform unauthorized insert/delete operations; periodically review user privileges.

Generated by OpenCVE AI on August 4, 2026 at 01:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Reading via Low-Privilege Access Control in Oracle Call Center Technology

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Reading via Low-Privilege Access Control in Oracle Call Center Technology

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Modification in Oracle Call Center Technology

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Modification in Oracle Call Center Technology

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: RDBMS and UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Call Center Technology accessible data as well as unauthorized read access to a subset of Oracle Call Center Technology accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle call Center Technology
CPEs cpe:2.3:a:oracle:call_center_technology:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle call Center Technology
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Call Center Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:14:12.588Z

Reserved: 2026-07-08T15:52:20.744Z

Link: CVE-2026-61264

cve-icon Vulnrichment

Updated: 2026-07-22T18:14:09.164Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses