Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-61335

CVE-2026-61335: Oracle Product Workbench Auth Bypass Flaw

CVE-2026-61335 is an authentication bypass vulnerability in Oracle Product Workbench that allows low-privileged attackers to access and modify critical data. This article covers technical details, affected versions, and steps.

Published:

CVE-2026-61335 Overview

CVE-2026-61335 is a high-severity access control vulnerability affecting the Oracle Product Workbench component of Oracle E-Business Suite. The flaw resides in the Internal Operations component and impacts supported versions 12.2.3 through 12.2.15. An authenticated attacker with low privileges can exploit this vulnerability over HTTP to compromise Oracle Product Workbench. Successful exploitation allows unauthorized creation, deletion, or modification of critical data, and unauthorized read access to all data accessible through Oracle Product Workbench. Oracle addressed the issue in the July 2026 Critical Patch Update.

Critical Impact

A low-privileged network attacker can read, modify, or delete all data accessible to Oracle Product Workbench, breaking confidentiality and integrity of Oracle E-Business Suite records.

Affected Products

  • Oracle E-Business Suite - Oracle Product Workbench 12.2.3
  • Oracle E-Business Suite - Oracle Product Workbench versions 12.2.4 through 12.2.14
  • Oracle E-Business Suite - Oracle Product Workbench 12.2.15

Discovery Timeline

  • 2026-07-21 - CVE-2026-61335 published to NVD
  • 2026-07-22 - Last updated in NVD database

Technical Details for CVE-2026-61335

Vulnerability Analysis

CVE-2026-61335 is classified as an Improper Access Control weakness [CWE-284] in the Internal Operations component of Oracle Product Workbench. The vulnerability allows an authenticated user with minimal privileges to bypass access restrictions and interact with data objects that should be outside their authorization scope. Attackers reach the vulnerable code path through standard HTTP requests to the Oracle E-Business Suite application tier.

Because Oracle Product Workbench manages product master data, bills of materials, and change records, successful exploitation exposes core business information. Attackers can view, alter, or destroy records used across manufacturing, procurement, and lifecycle workflows. The vulnerability does not affect availability, but the loss of data integrity in a master data system can cascade into downstream Oracle E-Business Suite modules.

The EPSS model currently rates the likelihood of near-term exploitation as low, and no public proof-of-concept code has been observed. However, Oracle E-Business Suite has historically been a target for post-authentication attacks, and the low complexity of this issue makes it a candidate for chaining with credential theft or session hijacking.

Root Cause

The root cause is missing or insufficient authorization enforcement in the Internal Operations component of Oracle Product Workbench. The application does not adequately verify that the authenticated user is permitted to perform the requested read or write operation on the targeted resource. This aligns with the [CWE-284] Improper Access Control pattern.

Attack Vector

Exploitation requires network access to the Oracle E-Business Suite HTTP interface and a valid low-privileged account. The attacker sends crafted HTTP requests to Product Workbench endpoints to trigger unauthorized data access or manipulation. No user interaction is required and the attack complexity is low. Refer to the Oracle Critical Patch Update Advisory - July 2026 for vendor-supplied technical context.

Detection Methods for CVE-2026-61335

Indicators of Compromise

  • Unexpected create, update, or delete operations on Product Workbench records performed by low-privileged accounts.
  • HTTP access logs showing repeated requests to Internal Operations endpoints from unusual source addresses or user agents.
  • Audit log entries where the acting user lacks a documented business role for the modified product master data.

Detection Strategies

  • Enable and review Oracle E-Business Suite Sign-On Audit and Function Security audit trails for anomalous Product Workbench activity.
  • Baseline normal Product Workbench transaction volume per user and alert on deviations, especially bulk data reads or edits.
  • Correlate application-tier HTTP logs with database-level FND audit tables to identify authorization mismatches.

Monitoring Recommendations

  • Forward Oracle E-Business Suite application, middle-tier, and database logs to a centralized SIEM for correlation.
  • Monitor for privilege changes and new responsibilities being assigned to accounts prior to Product Workbench activity.
  • Track outbound data volume from application servers hosting Oracle E-Business Suite to detect bulk data exfiltration.

How to Mitigate CVE-2026-61335

Immediate Actions Required

  • Apply the July 2026 Oracle Critical Patch Update to all Oracle E-Business Suite 12.2.3 through 12.2.15 environments.
  • Inventory all Oracle Product Workbench instances and confirm patch status against the Oracle advisory.
  • Review and reduce the number of accounts with access to Product Workbench responsibilities.
  • Rotate credentials for any low-privileged account that showed anomalous activity before patching.

Patch Information

Oracle released fixes for CVE-2026-61335 in the July 2026 Critical Patch Update. Administrators should follow the guidance in the Oracle Critical Patch Update Advisory - July 2026 and apply the specific patches listed for Oracle E-Business Suite 12.2. Validate the patch in a non-production environment before rolling out to production, and rerun regression tests against custom Product Workbench extensions.

Workarounds

  • Restrict network access to the Oracle E-Business Suite application tier using firewall rules or reverse proxy allowlists.
  • Remove or restrict Product Workbench responsibilities from users who do not require them until patches are applied.
  • Enforce multi-factor authentication on all Oracle E-Business Suite accounts to reduce the risk of credential misuse.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.