CVE-2026-61002: High severity Oracle Oracle SOA Suite vulnerability
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply compensating controls by restricting network access to the Oracle SOA Suite B2B Engine over HTTP so that low-privileged attackers cannot reach it (e.g., restrict inbound HTTP traffic to trusted sources only).
Event History
Frequently Asked Questions
Which deployments are affected?
Affected supported versions are Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0, specifically the B2B Engine component.
What access does an attacker need to exploit this issue?
An attacker needs network access to the Oracle SOA Suite instance over HTTP and low-privileged credentials. No user interaction is required.
What is the potential impact of successful exploitation?
Successful exploitation can result in takeover of Oracle SOA Suite, with high confidentiality, integrity, and availability impact.