PatchSiren cyber security CVE debrief
CVE-2026-61220 Oracle Corporation CVE debrief
A vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration) allows an unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination. The supported version that is affected is 14.5.0.16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Origination, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as unauthorized read access to a subset of Oracle Banking Origination accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Users of Oracle Banking Origination product of Oracle Financial Services Applications, particularly those using version 14.5.0.16.0, should review and apply necessary patches to mitigate this vulnerability. The CVE record was published on 2026-07-21T22:18:53.347Z and has not been modified since then. The NVD entry is currently Received.
- Vendor
- Oracle Corporation
- Product
- Oracle Banking Origination
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Users of Oracle Banking Origination product of Oracle Financial Services Applications, particularly those using version 14.5.0.16.0, should review and apply necessary patches to mitigate this vulnerability.
Technical summary
A vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration) allows an unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Origination, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as unauthorized read access to a subset of Oracle Banking Origination accessible data.
Defensive priority
Medium priority due to CVSS score of 6.1 and potential impact on additional products. Users should review and apply necessary patches to mitigate this vulnerability, considering compensating controls and monitoring for suspicious activity and exception tracking. Conduct inventory checks to ensure version 14.5.0.16.0 is identified and remediated. This vulnerability requires human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Origination, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as unauthorized read access to a subset of Oracle Banking Origination accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). The supported version that is affected is 14.5.0.16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination. Users of Oracle Banking Origination product of Oracle Financial Services Applications, particularly those using version 14.5.0.16.0, should review and apply necessary patches to mitigate this vulnerability. A vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration) allows an unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Origination, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as unauthorized read access to a subset of Oracle Banking Origination accessible data. The CVE record was published on 2026-07-21T22:18:53.347Z and has not been modified since then. The NVD entry is currently Received. AI-assisted PatchSiren debrief based
Recommended defensive actions
- Review and apply patches provided by Oracle
- Implement compensating controls to limit access to Oracle Banking Origination
- Monitor for suspicious activity and exception tracking
- Conduct inventory checks to ensure version 14.5.0.16.0 is identified and remediated
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and affected versions. Oracle's security alert page may contain additional information and patches. Evidence limits suggest verifying the vulnerability with limited source detail. Defensive verification tasks include reviewing Oracle's security alert page for patches and additional information. The vulnerability affects Oracle Banking Origination product of Oracle Financial Services Applications, particularly version 14.5.0.16.0.
Official resources
-
CVE-2026-61220 CVE record
CVE.org
-
CVE-2026-61220 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:53.347Z and has not been modified since then.