Junglewise Threat Intelligence

CVE-2026-60578: Oracle Enterprise Command Center Framework unauthorized data access in Core

CVE-2026-60578 · Severity: high · CVSS 7.6 · Published 2026-07-21

Technologies: Oracle Enterprise Command Center Framework. Vendors: Oracle.

Executive brief

A vulnerability exists in the Core component of the Oracle Enterprise Command Center Framework, a tool used within Oracle E-Business Suite to visualize and analyze business data. A high-privileged attacker could exploit this flaw to gain unauthorized access to sensitive corporate data or modify existing records. Because this component integrates with other business systems, a successful attack could potentially impact the security and integrity of additional connected products.

Technical details

This vulnerability affects the Core component of Oracle Enterprise Command Center Framework version V16. It is classified as easily exploitable by a high-privileged attacker with network access via HTTP. The exploit results in a 'scope change' (CVSS S:C), meaning the impact extends beyond the Command Center Framework to other integrated products within the Oracle E-Business Suite ecosystem. Successful exploitation allows for unauthorized read access to all accessible data (Confidentiality: High) and unauthorized modification, insertion, or deletion of some data (Integrity: Low). The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle Enterprise Command Center Framework V16

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60578 by Oracle.
  • 2026-07-21: advisory: NVD entry created.

References

Related threats