Junglewise Threat Intelligence

CVE-2026-60176: Oracle Payments unauthorized data access in File Transmission

CVE-2026-60176 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle Payments. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the File Transmission component of Oracle Payments, a module within the Oracle E-Business Suite used for managing financial transactions and electronic funds transfers. An attacker with low-level user credentials can exploit this flaw over the network to gain unauthorized access to sensitive financial data. This could lead to a significant breach of confidential information or a partial disruption of payment processing services.

Technical details

This vulnerability affects the File Transmission component of Oracle Payments within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network reachability via HTTP. Successful exploitation allows an attacker to gain unauthorized access to critical data or complete access to all data accessible by the Oracle Payments module. Additionally, the attacker can cause a partial denial of service (DoS) affecting the availability of the payment system. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation Oracle Payments 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle in the July 2026 CPU
  • 2026-07-21: advisory: NVD publication date

References

Related threats