Junglewise Threat Intelligence

CVE-2026-60580: Oracle Enterprise Command Center Framework takeover in Core component

CVE-2026-60580 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Enterprise Command Center Framework. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Oracle Enterprise Command Center Framework, a component of the Oracle E-Business Suite used for data visualization and operational insights. An attacker with access to the local network segment can completely take over the application without needing a username or password. This could lead to a total loss of data confidentiality, system integrity, and service availability for the affected business operations.

Technical details

A vulnerability in the Core component of Oracle Enterprise Command Center Framework (Oracle E-Business Suite) allows for a complete system takeover. The flaw is classified as easily exploitable and does not require authentication or user interaction. The attack vector is restricted to the 'Adjacent' network, meaning the attacker must be on the same physical or logical network segment (such as the same local area network) as the target hardware. Successful exploitation results in a total compromise of confidentiality, integrity, and availability (CVSS 8.8). The issue affects version V16 and was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Enterprise Command Center Framework V16

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats