SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61041 2026-07-21

CVE-2026-61041: Critical Takeover Flaw in Oracle Demantra Demand Management

"A critical (CVSS 9.9) vulnerability in Oracle Demantra Demand Management allows a low-privileged, network-based attacker to fully compromise the product and impact adjacent systems via a scope change."

A critical (CVSS 9.9) vulnerability in Oracle Demantra Demand Management allows a low-privileged, network-based attacker to fully compromise the product and impact adjacent systems via a scope change.

What Is It

CVE-2026-61041 is a critical vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain, within the Product Security component. Oracle rates it CVSS 3.1 Base Score 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The flaw is easily exploitable: a low-privileged attacker with network access over HTTP can compromise Oracle Demantra Demand Management, resulting in full takeover of the product.

Why It Matters

The vulnerability carries high impacts across confidentiality, integrity, and availability. Notably, the CVSS scope is "changed" (S:C): while the flaw resides in Oracle Demantra Demand Management, successful attacks may significantly impact additional products beyond the vulnerable component. Combined with low attack complexity, no user interaction, and only low privileges required, this makes the flaw an attractive target for attackers who gain a foothold on the network.

What's Vulnerable

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators running affected versions (12.2.3–12.2.15) should apply the fixes referenced in the Oracle Critical Patch Update Advisory for July 2026. No CISA KEV entry confirming active exploitation was supplied with this record.

Sources