Junglewise Threat Intelligence

CVE-2026-60687: Oracle E-Business Suite information disclosure in U.S. Federal Financials

CVE-2026-60687 · Severity: medium · CVSS 6.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle U.S. Federal Financials, a component of the Oracle E-Business Suite used by government agencies for financial management, contains a security vulnerability in its Internal Operations component. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to sensitive financial data. While the vulnerability is specific to the Federal Financials module, a successful attack could potentially impact other connected systems and data within the organization.

Technical details

A vulnerability exists in the Internal Operations component of Oracle U.S. Federal Financials (Oracle E-Business Suite). The flaw allows an unauthenticated attacker with network access via HTTPS to compromise the system. The vulnerability is classified as difficult to exploit (High Attack Complexity), but it carries a 'Scope Change' impact, meaning a successful exploit can affect components beyond the immediate security scope of the Federal Financials product. The primary impact is a loss of confidentiality, potentially resulting in unauthorized access to all accessible data within the module. Affected versions include 12.2.3 through 12.2.15. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle E-Business Suite (U.S. Federal Financials) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats