CVE-2026-61269: Medium severity Oracle Oracle E-Business Suite - Product Workbench (WebUI) vulnerability
Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Workbench accessible data as well as unauthorized read access to a subset of Oracle Product Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Workbench. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61269?
The severity of CVE-2026-61269 is rated as medium, with a CVSS score of 6.3.
How do I fix CVE-2026-61269?
To fix CVE-2026-61269, you should apply the latest security patches provided by Oracle for affected versions of the E-Business Suite.
What products are affected by CVE-2026-61269?
CVE-2026-61269 affects Oracle E-Business Suite versions 12.2.3 to 12.2.15, specifically the Product Workbench component.
Can CVE-2026-61269 be exploited remotely?
Yes, CVE-2026-61269 can be exploited by a low-privileged attacker with network access via HTTP.
What type of attack can be carried out using CVE-2026-61269?
The vulnerability allows potential attackers to compromise the Oracle Product Workbench, which may lead to unauthorized access or data manipulation.