Junglewise Threat Intelligence

CVE-2026-60172: Oracle Autonomous Health Framework compromise in Developer triaging platform

CVE-2026-60172 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle Autonomous Health Framework. Vendors: Oracle.

Executive brief

A vulnerability in the Oracle Autonomous Health Framework's developer triaging platform could allow a highly privileged user to take full control of the framework. To succeed, the attacker must already have access to the underlying infrastructure and trick another user into performing a specific action. An exploit could lead to a complete compromise of the health monitoring system, affecting its availability and the integrity of its data.

Technical details

This vulnerability exists in the Developer triaging platform component of Oracle Autonomous Health Framework versions 26.0.0, 26.1.0, and 26.2.0. It is classified as difficult to exploit (AC:H) and requires the attacker to have high privileges (PR:H) and local logon access to the infrastructure. A successful attack also requires user interaction (UI:R) from a separate individual. If exploited, the attacker can achieve a complete takeover of the framework, impacting confidentiality, integrity, and availability. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Autonomous Health Framework 26.0.0, 26.1.0, 26.2.0

Timeline

  • 2026-07-21: advisory: Published as part of Oracle Critical Patch Update July 2026

References

Related threats