PatchSiren cyber security CVE debrief
CVE-2026-61275 Oracle Corporation CVE debrief
A vulnerability was discovered in Oracle Product Hub, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61275, is related to Role-Based Security and has a CVSS score of 6.3, indicating a medium severity level. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Product Hub, potentially leading to unauthorized data access and partial denial of service.
- Vendor
- Oracle Corporation
- Product
- Oracle Product Hub
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Organizations using Oracle Product Hub versions 12.2.3-12.2.15 should prioritize patching this vulnerability to prevent potential exploitation. Affected operators and platform administrators should assess the risk and implement compensating controls if immediate patching is not feasible. Vulnerability management and security teams should monitor for suspicious activity and ensure thorough inventory checks are conducted to identify and remediate exposed systems.
Technical summary
The CVE-2026-61275 vulnerability in Oracle Product Hub's Role-Based Security component allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized update, insert, or delete access to some Oracle Product Hub data, unauthorized read access to a subset of data, and partial denial of service. The CVSS 3.1 vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L, with a base score of 6.3, indicating medium severity.
Defensive priority
Medium priority should be given to patching CVE-2026-61275 in Oracle Product Hub, given its potential impact on data integrity and availability.
Recommended defensive actions
- Apply the security patch provided by Oracle for CVE-2026-61275
- Conduct a thorough inventory check to identify affected systems
- Implement compensating controls to monitor and restrict access to Oracle Product Hub
- Verify the effectiveness of the patch through retesting
- Monitor for any suspicious activity related to this vulnerability
Evidence notes
The CVE record was published on 2026-07-21T22:18:57.743Z and last modified on 2026-07-22T16:18:44.867Z. The NVD entry is currently in the 'Received' status. Oracle has provided a security alert for this vulnerability (source reference: [email protected]).
Official resources
-
CVE-2026-61275 CVE record
CVE.org
-
CVE-2026-61275 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:57.743Z and has not been modified since then. The NVD entry is currently Received.