PatchSiren cyber security CVE debrief
CVE-2026-61217 Oracle Corporation CVE debrief
A vulnerability was discovered in the Oracle Security Service product of Oracle Fusion Middleware. The affected version is 12.2.1.4.0. This difficult-to-exploit vulnerability allows a low-privileged attacker with network access via TLS to compromise Oracle Security Service. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Security Service accessible data, as well as unauthorized access to critical data or complete access to all Oracle Security Service accessible data. The vulnerability has a CVSS 3.1 Base Score of 6.4, indicating a medium severity level.
- Vendor
- Oracle Corporation
- Product
- Oracle Security Service
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Administrators and users of Oracle Security Service version 12.2.1.4.0 should be aware of this vulnerability and take necessary precautions. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified.
Technical summary
The vulnerability is located in the Oracle SSL API component of Oracle Security Service. It has a CVSS 3.1 Base Score of 6.4, indicating a medium severity level. The CVSS Vector is (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N). The vulnerability allows a low-privileged attacker with network access via TLS to compromise Oracle Security Service. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Security Service accessible data, as well as unauthorized access to critical data or complete access to all Oracle Security Service accessible data. The affected version is 12.2.1.4.0.
Defensive priority
Medium priority should be given to patching or mitigating this vulnerability, as it requires human interaction and has a medium CVSS score.
Recommended defensive actions
- Apply the patch from Oracle as soon as possible
- Restrict network access to Oracle Security Service
- Monitor for suspicious activity
- Implement compensating controls
- Verify and update inventory
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-07-21T22:18:53.127Z and was last modified on 2026-07-22T19:17:09.110Z. The NVD entry is currently in the 'Received' status. This information is based on the supplied source corpus and may not reflect the current status of the vulnerability. Defenders should verify the current status and affected scope with Oracle. The vulnerability affects Oracle Security Service version 12.2.1.4.0. Human interaction is required for successful exploitation.
Official resources
-
CVE-2026-61217 CVE record
CVE.org
-
CVE-2026-61217 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:53.127Z and has not been modified since then. The NVD entry is currently Received.