A critical (CVSS 9.6) vulnerability in Oracle Banking Trade Finance Process Management lets an unauthenticated, network-based attacker compromise the platform and reach data across additional connected products.
What Is It
CVE-2026-61097 is a vulnerability in the Common component of Oracle Banking Trade Finance Process Management, part of Oracle Financial Services Applications. Per the NVD record, it is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks require human interaction from a person other than the attacker. Because the vulnerability carries a scope change, exploitation may significantly impact additional products beyond the vulnerable component. It carries a CVSS 3.1 base score of 9.6 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L.
Why It Matters
The score of 9.6 reflects high confidentiality and integrity impact plus a partial denial-of-service capability. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, up to all data accessible to the platform, as well as unauthorized read access to that data and a partial denial of service. The scope change means damage is not contained to the vulnerable product alone, raising the stakes for connected financial systems. No CISA KEV entry was supplied, so active exploitation is not confirmed in this source material.
What's Vulnerable
- Product: Oracle Banking Trade Finance Process Management (component: Common)
- Affected versions: 14.6.0 through 14.8.0
- Vendor: Oracle Corporation
Patch Status
The supplied reference points to Oracle's Critical Patch Update advisory for July 2026 (cpujul2026.html). Organizations running affected versions 14.6.0–14.8.0 should consult that advisory and apply the corresponding fixes. No separate KEV-mandated remediation deadline was provided in the source material.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-61097, https://nvd.nist.gov/vuln/detail/CVE-2026-61097