Junglewise Threat Intelligence

CVE-2026-60588: Oracle Enterprise Asset Management data manipulation in Work Definition Issues

CVE-2026-60588 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Enterprise Asset Management. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Enterprise Asset Management, a tool used by organizations to manage physical assets and maintenance operations. An authorized user with low-level permissions can exploit this flaw over the network to view, modify, or delete certain business data. This could lead to unauthorized changes in maintenance records or the exposure of sensitive operational information.

Technical details

A vulnerability in the Work Definition Issues component of Oracle Enterprise Asset Management (part of Oracle E-Business Suite) allows for unauthorized data manipulation. The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. Successful exploitation enables the attacker to read a subset of data and perform unauthorized updates, insertions, or deletions of accessible data. The vulnerability affects versions 12.2.3 through 12.2.15. Oracle has addressed this issue in the July 2026 Critical Patch Update.

Affected products

  • Oracle Enterprise Asset Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats