Junglewise Threat Intelligence

CVE-2026-60683: Oracle Process Manufacturing Regulatory Management data breach in Internal Operations

CVE-2026-60683 · Severity: high · CVSS 7.7 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Regulatory Management, a tool used by businesses to manage regulatory compliance and safety data. A low-privileged user can exploit this flaw over the network to gain unauthorized access to sensitive data. This could lead to a significant breach of confidential regulatory information and potentially impact other integrated business systems.

Technical details

This vulnerability affects the Internal Operations component of Oracle Process Manufacturing Regulatory Management within Oracle E-Business Suite. It is classified as an unauthorized data access issue that is easily exploitable via HTTP. An attacker with low-level privileges and network access can bypass intended confidentiality restrictions to access all data within the component. Notably, the vulnerability involves a scope change (CVSS S:C), meaning an exploit can impact resources beyond the immediate security scope of the affected product. Affected versions range from 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Process Manufacturing Regulatory Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60683
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats