Oracle ASCP Core HTTP PrivEsc v12.2.312.2.15
CVE-2026-61039 Published on July 21, 2026
Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Supply Chain Planning. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Supply Chain Planning. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Vulnerability Analysis
CVE-2026-61039 can be exploited with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Products Associated with CVE-2026-61039
stack.watch emails you whenever new vulnerabilities are published in Oracle Advanced Supply Chain Planning or Oracle. Just hit a watch button to start following.
Affected Versions
Oracle Corporation Oracle Advanced Supply Chain Planning:- Version 12.2.3, <= 12.2.15 is affected.