Executive brief
Oracle Cost Management, a component of the Oracle E-Business Suite used for tracking and managing manufacturing and supply chain costs, contains a security vulnerability in its Enterprise Command Center. A high-privileged attacker could exploit this flaw to gain unauthorized access to sensitive financial data. This could result in the unauthorized viewing, modification, or deletion of critical business records, potentially impacting financial reporting and operational integrity.
Technical details
A vulnerability exists in the Enterprise Command Center component of Oracle Cost Management (Oracle E-Business Suite) version V16. The flaw is classified as easily exploitable and allows a high-privileged attacker with network access via HTTP to compromise the system. Successful exploitation grants the attacker unauthorized creation, deletion, or modification access to critical data, as well as complete read access to all data accessible by the Cost Management module. The CVSS 3.1 vector indicates a network attack vector with low complexity, requiring high privileges and no user interaction, impacting confidentiality and integrity but not availability.
Affected products
- Oracle Cost Management (Enterprise Command Center) V16
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability as part of the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: CVE-2026-60165 was published to the NVD.