Junglewise Threat Intelligence

CVE-2026-60573: Oracle Partner Management vulnerability in Partner Dashboard

CVE-2026-60573 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle Partner Management. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Partner Dashboard component of Oracle Partner Management, a tool used by businesses to manage relationships and data with external partners. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain partner data. Additionally, an exploit could cause a partial service outage, disrupting normal business operations and partner interactions.

Technical details

This vulnerability affects the Partner Dashboard component of Oracle Partner Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTPS. Successful exploitation allows an attacker to perform unauthorized read, update, insert, or delete operations on a subset of accessible data. It also enables a partial denial of service (DoS) attack. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Oracle Partner Management (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats