Summary
CVE-2026-61138 is a high-severity improper access control vulnerability (CWE-284) affecting Oracle Complex Maintenance, Repair and Overhaul (CMRO), a fully web-based module within Oracle E-Business Suite (EBS). The flaw is exploitable over the network without any authentication or user interaction, allowing remote attackers to gain unauthorized read access to sensitive CMRO data and perform limited unauthorized data manipulation. It was published on July 21, 2026 as part of Oracle’s July 2026 Critical Patch Update.
Technical details
- Root cause: An improper access control flaw exists in the Internal Operations component of Oracle CMRO, accessible over HTTP. The control deficiency allows network-based requests to bypass authorization checks that should gate access to sensitive application data.
- Trigger conditions: No authentication or user interaction is required. Attack complexity is rated High (AC:H), indicating that exploitation depends on specific conditions or configurations that may not be present in all deployments, but do apply to a subset of production environments.
- Attack vector: Network (AV:N) — exploitable remotely over the internet via HTTP, with no prior foothold on the target system required.
- Impact: Successful exploitation enables unauthorized read access to critical or complete CMRO-accessible data (Confidentiality: High), and unauthorized insert, update, or delete access to a subset of CMRO data (Integrity: Low). The Changed scope (S:C) indicates the impact extends beyond the vulnerable component itself, affecting resources managed by a different security context within the EBS environment.
Affected software
- Oracle Complex Maintenance, Repair and Overhaul (Oracle E-Business Suite) versions 12.2.3 through 12.2.15
Severity
- CVSS v3.1 Base Score: 7.5 (High)
- Vector String:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Mitigation and recommended actions
- Immediate action: Apply the Oracle July 2026 Critical Patch Update (CPU), which contains the vendor-provided fix for this vulnerability. Oracle’s advisory provides patch availability details and application instructions.
- Network mitigation: If patching cannot be completed immediately, restrict external network access to Oracle EBS/CMRO-facing HTTP endpoints using perimeter controls (firewall rules, reverse proxy allowlisting) to limit exposure to untrusted networks. This does not eliminate the vulnerability but reduces the attack surface while patching is scheduled.
- Prioritize instances where CMRO Internal Operations endpoints are internet-accessible, as these represent the most direct risk.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

