PatchSiren cyber security CVE debrief
CVE-2026-61200 Oracle Corporation CVE debrief
A vulnerability exists in Oracle Labor Distribution, a component of Oracle E-Business Suite. The affected versions are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks can result in unauthorized update, insert or delete access to some accessible data and unauthorized read access to a subset of accessible data. The CVSS 3.1 Base Score is 5.4, indicating medium severity with Confidentiality and Integrity impacts.
- Vendor
- Oracle Corporation
- Product
- Oracle Labor Distribution
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Organizations using Oracle Labor Distribution within Oracle E-Business Suite versions 12.2.3-12.2.15 should prioritize patching this vulnerability. Low-privileged attackers with network access via HTTP can exploit this vulnerability, potentially leading to data tampering and information disclosure.
Technical summary
The vulnerability in Oracle Labor Distribution (component: Internal Operations) of Oracle E-Business Suite (versions 12.2.3-12.2.15) is easily exploitable. A low-privileged attacker with network access via HTTP can compromise Oracle Labor Distribution. Successful attacks can lead to unauthorized update, insert or delete access to some accessible data and unauthorized read access to a subset of accessible data. The CVSS 3.1 score is 5.4 (Confidentiality and Integrity impacts), with the vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N.
Defensive priority
Apply patches or updates provided by Oracle to address the vulnerability in Oracle Labor Distribution. Restrict network access to the affected systems and monitor for suspicious activities.
Recommended defensive actions
- Apply patches or updates provided by Oracle to address the vulnerability in Oracle Labor Distribution.
- Restrict network access to the affected systems.
- Monitor for suspicious activities and implement additional security measures to protect against potential attacks.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was published on 2026-07-21T22:18:51.730Z and was last modified on 2026-07-22T19:17:08.307Z. The NVD entry is currently in the 'Received' status. Oracle has provided a security alert for this vulnerability (reference: https://www.oracle.com/security-alerts/cpujul2026.html).
Official resources
-
CVE-2026-61200 CVE record
CVE.org
-
CVE-2026-61200 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:51.730Z and has not been modified since then. The NVD entry is currently Received.