Junglewise Threat Intelligence

CVE-2026-60544: Oracle SOA Suite unauthorized data access in B2B Engine

CVE-2026-60544 · Severity: high · CVSS 8.2 · Published 2026-07-21

Technologies: Oracle SOA Suite. Vendors: Oracle.

Executive brief

A vulnerability in the B2B Engine component of Oracle SOA Suite allows an unauthenticated attacker to access sensitive data over the network. Oracle SOA Suite is used by businesses to integrate different software applications and automate business processes. An exploit could lead to the theft of critical business data or cause a partial disruption of the service, potentially impacting automated workflows and data exchange with partners.

Technical details

This vulnerability exists in the B2B Engine component of Oracle SOA Suite within Oracle Fusion Middleware. It is classified as an easily exploitable flaw that can be triggered by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for unauthorized access to critical data or complete access to all data accessible by the SOA Suite, as well as the ability to cause a partial denial of service (DoS). The vulnerability has a CVSS 3.1 base score of 8.2, reflecting high confidentiality impact and low availability impact. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle SOA Suite 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Initial publication of the vulnerability by Oracle and NVD.

References

Related threats