Junglewise Threat Intelligence

CVE-2026-60685: Oracle iSupport unauthorized data access in Internal Operations

CVE-2026-60685 · Severity: medium · CVSS 6.1 · Published 2026-07-21

Technologies: Oracle Isupport. Vendors: Oracle.

Executive brief

Oracle iSupport, a customer service portal within the Oracle E-Business Suite, contains a vulnerability that could allow an unauthorized person to view or modify certain data. To exploit this, an attacker would need to trick a legitimate user into performing a specific action, such as clicking a malicious link. If successful, this could lead to unauthorized changes to customer support records or the exposure of sensitive information.

Technical details

A vulnerability in the Internal Operations component of Oracle iSupport (Oracle E-Business Suite) allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is characterized by a CVSS 'Scope Change,' suggesting it may be a Cross-Site Scripting (XSS) or similar injection vulnerability that allows an attacker to impact other components beyond iSupport. Exploitation requires human interaction from a person other than the attacker (UI:R). Successful attacks can result in unauthorized read, update, insert, or delete access to a subset of data. Affected versions include 12.2.3 through 12.2.15.

Affected products

  • Oracle iSupport 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats