Junglewise Threat Intelligence

CVE-2026-60583: Oracle Transportation Management compromise via Install component

CVE-2026-60583 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Transportation Management. Vendors: Oracle.

Executive brief

Oracle Transportation Management, a software suite used by businesses to manage global supply chain and logistics operations, contains a critical security vulnerability in its installation component. An attacker with low-level user access to the network can exploit this flaw to gain full control over the system. This could lead to the theft of sensitive shipping data, disruption of logistics operations, and unauthorized changes to supply chain records.

Technical details

This vulnerability exists in the 'Install' component of Oracle Transportation Management version 6.5.3. It is classified as easily exploitable, requiring only low-privileged (PR:L) authentication and network access via HTTP (AV:N). The flaw allows an attacker to bypass security controls to achieve a complete takeover of the application, impacting confidentiality, integrity, and availability. While the specific CWE is not listed, the impact suggests a significant authorization or injection flaw within the installation routines. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Transportation Management 6.5.3

Timeline

  • 2026-07-21: disclosed: Published by Oracle and NVD
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats