Junglewise Threat Intelligence

CVE-2026-60541: Oracle SOA Suite remote compromise in Enterprise Scheduling System

CVE-2026-60541 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle SOA Suite. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in the Enterprise Scheduling System component of Oracle SOA Suite, a platform used for connecting and automating business processes. This flaw allows an unauthenticated attacker to remotely take full control of the system over the network. An exploit could lead to a total loss of data confidentiality, system integrity, and service availability, potentially disrupting core business operations and exposing sensitive information.

Technical details

This vulnerability exists within the Enterprise Scheduling System component of Oracle SOA Suite (part of Oracle Fusion Middleware). It is classified as easily exploitable, requiring no authentication or user interaction (PR:N/UI:N). An attacker can exploit this flaw over the network via HTTP to achieve a complete takeover of the affected Oracle SOA Suite instance. The vulnerability impacts confidentiality, integrity, and availability with a CVSS base score of 9.8. Affected versions are 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.

Affected products

  • Oracle SOA Suite 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats