Summary
CVE-2026-61309 is a high-severity improper access control vulnerability (CWE-284) in Oracle In-Memory Cost Management for Discrete Industries, a component of Oracle E-Business Suite (EBS). The flaw allows unauthenticated, network-based attackers to access critical data via HTTP without any user interaction, and was addressed in Oracle’s July 2026 Critical Patch Update. All EBS deployments running the affected module on versions 12.2.3 through 12.2.15 are at risk.
Technical details
- Root cause: Improper access control in the Internal Operations component of Oracle In-Memory Cost Management for Discrete Industries, allowing requests to succeed without valid credentials.
- Trigger conditions: An attacker with network access to the EBS web tier (HTTP) can send a crafted request to the vulnerable component — no authentication, no user interaction, and no elevated privilege are required.
- Attack vector: Network-accessible (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High confidentiality impact — attackers can gain unauthorized read access to sensitive cost management data (cost simulations, profit analysis, cost planning data, and related financial information). No integrity or availability impact is indicated.
Affected software
- Oracle In-Memory Cost Management for Discrete Industries (Oracle E-Business Suite), versions 12.2.3 through 12.2.15
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle E-Business Suite patches distributed as part of Oracle’s July 2026 Critical Patch Update. Patch delivery is managed through Oracle My Oracle Support (reference: Oracle EBS Release 12 Critical Patch Update Knowledge Document, July 2026, MOS Article ID KA923).
- If patching cannot be applied immediately:
- Restrict network access to Oracle EBS web-tier endpoints at the perimeter firewall — limit HTTP/HTTPS access to the EBS application server to trusted internal IP ranges only.
- Consider disabling or blocking access to the Oracle In-Memory Cost Management servlet endpoints until the CPU patch can be applied.
- Monitor EBS access logs for anomalous unauthenticated requests to Internal Operations endpoints.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

