Junglewise Threat Intelligence

CVE-2026-60675: Oracle Applications Framework takeover in Search Bean

CVE-2026-60675 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Applications Framework. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Applications Framework, a core component of the Oracle E-Business Suite used for building and deploying business applications. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the framework. This could lead to the unauthorized access, modification, or deletion of sensitive business data and a total disruption of services.

Technical details

A vulnerability in the Search Bean component of the Oracle Applications Framework (part of Oracle E-Business Suite) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation grants the attacker high-impact access to confidentiality, integrity, and availability (C/I/A). Affected versions include 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Applications Framework 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats