CVE-2026-61262: Medium severity Oracle Oracle Teleservice vulnerability
Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Supported versions that are affected are 12.2.3-12.215. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Teleservice. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Teleservice accessible data as well as unauthorized read access to a subset of Oracle Teleservice accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite - Service Diagnostics Scripts (Oracle Teleservice)to a version that resolves this vulnerability.Fixed in 12.2.3-12.215
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61262?
The severity of CVE-2026-61262 is rated as medium with a score of 6.5.
How do I fix CVE-2026-61262?
To fix CVE-2026-61262, apply the latest security patches provided by Oracle for the affected versions of Oracle Teleservice.
Which products are affected by CVE-2026-61262?
CVE-2026-61262 affects the Oracle Teleservice component of Oracle E-Business Suite, specifically versions 12.2.3 to 12.215.
What is the risk associated with CVE-2026-61262?
CVE-2026-61262 poses an easily exploitable risk that allows unauthenticated attackers with network access via HTTP to compromise Oracle Teleservice.
What does CVE-2026-61262 affect in terms of confidentiality and integrity?
CVE-2026-61262 affects the confidentiality and integrity of the system, as indicated by the low scores in both categories.