Description
Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Customers Online accessible data as well as unauthorized access to critical data or complete access to all Oracle Customers Online accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the access control logic of Oracle Customers Online's Internal Operations component permits an attacker with a low‑privilege network presence over HTTP to create, delete, modify, or read critical records. The vulnerability, identified as CWE‑284, directly impacts confidentiality and integrity, allowing full unauthorized access to any data available through Customers Online. The CVSS v3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) assigns a base score of 8.1.

Affected Systems

Affected are Oracle Customers Online versions 12.2.3 through 12.2.15 within Oracle E‑Business Suite. The advisory references the July 2026 CPU, where Oracle released a fix for these releases.

Risk and Exploitability

While the EPSS score is below 1%, suggesting a low probability of exploitation, the CVSS score indicates high severity, and the vulnerability is not yet in the CISA KEV catalog. An attacker only requires low‑privilege credentials and HTTP reach, making the attack straightforward for anyone with network access to the application. The lack of remote user interface and the dependency on low‑privilege accounts means exploitation is relatively easy for insiders or compromised internal users.

Generated by OpenCVE AI on August 4, 2026 at 01:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Enterprise Edition patch released in the July 2026 CPU that addresses Customers Online, ensuring the system is upgraded past version 12.2.15.
  • If a patch is not yet available, restrict HTTP access to the Internal Operations component to trusted IP ranges or place it behind a dedicated firewall to narrow the attack surface.
  • Strengthen application‑level access controls so that users interacting with Customers Online possess the minimum privileges necessary, and enable comprehensive audit logging to detect any unauthorized modification attempts.

Generated by OpenCVE AI on August 4, 2026 at 01:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Allows Unauthorized Data Manipulation in Oracle Customers Online

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Allows Unauthorized Data Manipulation in Oracle Customers Online

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Bypass in Oracle Customers Online Leading to Unauthorized Data Modification

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Bypass in Oracle Customers Online Leading to Unauthorized Data Modification

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Customers Online accessible data as well as unauthorized access to critical data or complete access to all Oracle Customers Online accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle customers Online
CPEs cpe:2.3:a:oracle:customers_online:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle customers Online
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Customers Online
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:09:42.935Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61297

cve-icon Vulnrichment

Updated: 2026-07-22T18:09:39.551Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses