A critical (CVSS 9.9) vulnerability in Oracle Demantra Demand Management allows a low-privileged, network-based attacker to fully compromise the product and impact adjacent systems via a scope change.
What Is It
CVE-2026-61041 is a critical vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain, within the Product Security component. Oracle rates it CVSS 3.1 Base Score 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The flaw is easily exploitable: a low-privileged attacker with network access over HTTP can compromise Oracle Demantra Demand Management, resulting in full takeover of the product.
Why It Matters
The vulnerability carries high impacts across confidentiality, integrity, and availability. Notably, the CVSS scope is "changed" (S:C): while the flaw resides in Oracle Demantra Demand Management, successful attacks may significantly impact additional products beyond the vulnerable component. Combined with low attack complexity, no user interaction, and only low privileges required, this makes the flaw an attractive target for attackers who gain a foothold on the network.
What's Vulnerable
- Product: Oracle Demantra Demand Management (Oracle Supply Chain), component: Product Security
- Vendor: Oracle Corporation
- Affected versions: 12.2.3 through 12.2.15
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators running affected versions (12.2.3–12.2.15) should apply the fixes referenced in the Oracle Critical Patch Update Advisory for July 2026. No CISA KEV entry confirming active exploitation was supplied with this record.
Sources
- Oracle Critical Patch Update Advisory - July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD - CVE-2026-61041; https://nvd.nist.gov/vuln/detail/CVE-2026-61041