Description
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The supported version that is affected is 12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. While the vulnerability is in Oracle Advanced Benefits, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Benefits accessible data. CVSS 3.1 Base Score 7.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).
Published: 2026-07-21
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle Advanced Benefits is an improper access control flaw (CWE‑284) that allows an attacker with low privileges to access the system through a network HTTP endpoint and create, delete, or modify critical data. The impact is a loss of data integrity, as an attacker can alter or remove information that the business considers reliable. The issue is not about privilege escalation; the attacker simply needs low‑privileged credentials that would normally restrict them from performing these actions.

Affected Systems

Oracle Corporation’s Advanced Benefits version 12.2.15 is affected, specifically within the Internal Operations component. The CVE notes that the flaw’s scope can impact additional Oracle E‑Business Suite products, potentially allowing unauthorized data manipulation beyond the Benefits application.

Risk and Exploitability

The CVSS 3.1 base score of 7.7 indicates a high integrity impact. The EPSS score is below 1%, suggesting that exploitation is currently low probability, yet the HTTP entry point can be reached over the network, so the flaw remains remotely exploitable. The CVE is not listed in the CISA KEV catalog, but the potential for widespread data alteration across the suite elevates its importance for organizations running the affected version.

Generated by OpenCVE AI on August 4, 2026 at 00:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or upgrade Oracle Advanced Benefits to a version that resolves CVE‑2026‑61324 as noted in Oracle’s CPU July 2026 advisory
  • Restrict network access to the Advanced Benefits HTTP service by configuring firewalls or ACLs so that only trusted hosts can reach the service
  • Review and enforce strict role‑based access controls within Advanced Benefits, removing unnecessary privileges and ensuring that only authorized users can perform create, delete, or modify operations

Generated by OpenCVE AI on August 4, 2026 at 00:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Advanced Benefits Enables Unauthorized Data Modification

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Advanced Benefits Enables Unauthorized Data Modification

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Access Control Bypass in Oracle Advanced Benefits

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Access Control Bypass in Oracle Advanced Benefits

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Internal Operations). The supported version that is affected is 12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. While the vulnerability is in Oracle Advanced Benefits, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Benefits accessible data. CVSS 3.1 Base Score 7.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).
First Time appeared Oracle
Oracle advanced Benefits
CPEs cpe:2.3:a:oracle:advanced_benefits:12.2.15:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Benefits
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'}


Subscriptions

Oracle Advanced Benefits
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:54:33.254Z

Reserved: 2026-07-08T15:52:20.747Z

Link: CVE-2026-61324

cve-icon Vulnrichment

Updated: 2026-07-22T17:54:29.327Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses