CVE-2026-61266: SQL Injection
Vulnerability in the Oracle Supply Chain Globalization product of Oracle E-Business Suite (component: Copy Inventory Organization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Supply Chain Globalization. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Supply Chain Globalization accessible data as well as unauthorized read access to a subset of Oracle Supply Chain Globalization accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Supply Chain Globalization. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61266?
The severity of CVE-2026-61266 is medium, rated at 6.3 on the CVSS scale.
How do I fix CVE-2026-61266?
To fix CVE-2026-61266, you should apply the recommended security patches provided by Oracle for affected versions of Oracle E-Business Suite.
What are the affected versions of CVE-2026-61266?
The affected versions of CVE-2026-61266 are Oracle E-Business Suite versions 12.2.3 through 12.2.15.
What type of attack does CVE-2026-61266 facilitate?
CVE-2026-61266 facilitates SQL injection and information leakage attacks by low privileged attackers with network access.
Can CVE-2026-61266 be exploited remotely?
Yes, CVE-2026-61266 can be exploited remotely by attackers with network access via HTTP.