CVE-2026-61090: High severity Oracle Oracle E-Business Suite - Oracle Project Foundation vulnerability
Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Project Foundation executes to compromise Oracle Project Foundation. Successful attacks of this vulnerability can result in takeover of Oracle Project Foundation. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite - Oracle Project Foundation (component: Miscellaneous)to a version that resolves this vulnerability.Fixed in 12.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61090?
The severity of CVE-2026-61090 is rated as high with a CVSS score of 7.8.
How do I fix CVE-2026-61090?
To remediate CVE-2026-61090, update to the latest versions above 12.2.15 of Oracle E-Business Suite.
What components are affected by CVE-2026-61090?
CVE-2026-61090 affects the Oracle Project Foundation component of Oracle E-Business Suite.
Who can exploit CVE-2026-61090?
CVE-2026-61090 can be exploited by a low privileged attacker with logon access to the infrastructure.
What impact does CVE-2026-61090 have on Oracle Project Foundation?
CVE-2026-61090 allows for potential unauthorized access and manipulation of sensitive data, as it has high impact on confidentiality, integrity, and availability.