Junglewise Threat Intelligence

CVE-2026-60310: Oracle Performance Management data manipulation in Appraisals

CVE-2026-60310 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Appraisals component of Oracle Performance Management, a tool used by organizations to manage employee evaluations and performance reviews. A low-privileged user could exploit this flaw to gain unauthorized access to sensitive performance data or modify records. This could lead to the exposure of confidential employee information or the unauthorized alteration of performance appraisals.

Technical details

A vulnerability in the Appraisals component of Oracle Performance Management (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to perform unauthorized read, update, insert, or delete operations on a subset of data accessible to the Performance Management module. The vulnerability affects versions 12.2.3 through 12.2.15. Oracle has addressed this issue in the July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation Performance Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.

References

Related threats