CVE-2026-61004 Overview
CVE-2026-61004 is a high-severity vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite, within the Internal Operations component. Supported versions 12.2.3 through 12.2.15 are affected. A low-privileged attacker with network access via HTTP can exploit the flaw without user interaction. Successful exploitation results in unauthorized read access as well as create, modify, or delete access to all data accessible by Oracle Landed Cost Management. Oracle addressed this issue in the July 2026 Critical Patch Update.
Critical Impact
An authenticated remote attacker can read and tamper with all data accessible by Oracle Landed Cost Management, compromising confidentiality and integrity of supply chain financial records.
Affected Products
- Oracle E-Business Suite - Oracle Landed Cost Management 12.2.3 through 12.2.15
- Component: Internal Operations
- Deployments exposing the affected HTTP endpoints to authenticated users
Discovery Timeline
- 2026-07-21 - CVE CVE-2026-61004 published to NVD
- 2026-07-21 - Last updated in NVD database
- July 2026 - Oracle releases fix in the July 2026 Critical Patch Update
Technical Details for CVE-2026-61004
Vulnerability Analysis
The vulnerability resides in the Internal Operations component of Oracle Landed Cost Management, part of Oracle E-Business Suite. It is classified as a broken access control issue that allows a low-privileged authenticated user to reach functionality or data that should be restricted. The attacker communicates with the application over HTTP and does not require user interaction. Successful exploitation grants read access to sensitive landed cost data and permits creation, modification, or deletion of records within the module's scope. The EPSS probability is 0.365% at the 29th percentile, indicating low observed exploitation activity to date.
Root Cause
Oracle has not published detailed root-cause information beyond the advisory. The advisory identifies the flaw as an authenticated network-accessible weakness in the Internal Operations component that fails to enforce authorization on operations affecting Landed Cost Management data. The impact profile is limited to confidentiality and integrity, with no availability effects, consistent with a data-access or business-logic authorization defect rather than a memory-corruption class issue.
Attack Vector
An attacker requires a valid low-privileged account on the affected Oracle E-Business Suite instance and network reachability to the Landed Cost Management HTTP interface. The attacker sends crafted HTTP requests to the vulnerable Internal Operations endpoints to invoke operations that read or alter data belonging to the module. No verified public proof-of-concept exists at the time of writing. Refer to the Oracle Security Alert July 2026 for authoritative technical details.
Detection Methods for CVE-2026-61004
Indicators of Compromise
- Unexpected HTTP requests from low-privileged user sessions to Landed Cost Management Internal Operations URLs on the Oracle E-Business Suite server
- Unauthorized create, update, or delete entries in Landed Cost Management audit tables performed by accounts without a business role in that module
- Anomalous data-export volumes originating from Landed Cost Management responsibilities
Detection Strategies
- Correlate Oracle E-Business Suite Sign-On Audit and FND audit trails with HTTP access logs to identify low-privileged users invoking Internal Operations endpoints
- Alert on Landed Cost Management table modifications by user IDs that lack the corresponding functional responsibility
- Baseline normal request patterns to /OA_HTML/ and Landed Cost Management servlets, then alert on deviations
Monitoring Recommendations
- Enable and forward Oracle E-Business Suite application, database, and web-tier logs to a centralized analytics platform
- Monitor authentication events for accounts newly granted access to Landed Cost Management responsibilities
- Track outbound data flows from the E-Business Suite application tier for signs of bulk exfiltration
How to Mitigate CVE-2026-61004
Immediate Actions Required
- Apply the July 2026 Oracle Critical Patch Update to all Oracle E-Business Suite 12.2.3 through 12.2.15 instances
- Inventory user accounts with access to Landed Cost Management and revoke unnecessary responsibilities
- Restrict network access to Oracle E-Business Suite HTTP endpoints to trusted user networks and VPNs
Patch Information
Oracle addressed CVE-2026-61004 in the July 2026 Critical Patch Update. Administrators should review the Oracle Security Alert July 2026 advisory, identify the specific patch identifier for their Oracle E-Business Suite 12.2.x release, and apply it following Oracle's documented patching procedure with adpatch or adop. Test in non-production environments prior to production rollout.
Workarounds
- No vendor-approved workaround has been published; patching is the authoritative remediation
- Reduce exposure by placing Oracle E-Business Suite behind a reverse proxy or Web Application Firewall that enforces authentication and URL allow-listing
- Enforce least-privilege on Landed Cost Management responsibilities until patches are applied
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

