CVE-2026-61328
MEDIUM
6.6
CVSS 3.1
Metadata
Severity & Metrics
6.6
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Oracle Corporation | Oracle Cost Management | — | 12.2.3 ≤ 12.2.15 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. |
| CWE-284 | adp | CWE-284 Improper Access Control |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 6.6 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
References (1)
- Oracle Advisory https://www.oracle.com/security-alerts/cpujul2026.html