Junglewise Threat Intelligence

CVE-2026-60688: Oracle E-Business Suite data manipulation in Oracle Scheduler Rules UI

CVE-2026-60688 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Scheduler component of the Oracle E-Business Suite, which is used by organizations to automate business processes and manage job scheduling. An authorized user with low-level permissions could exploit this flaw to view, modify, or delete sensitive scheduling data. Additionally, an attacker could disrupt operations by causing a partial service outage, potentially impacting automated business workflows.

Technical details

This vulnerability affects the Rules UI component of Oracle Scheduler within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system without user interaction. Successful exploitation enables unauthorized read, update, insert, or delete access to a subset of Oracle Scheduler data. It also allows an attacker to trigger a partial denial of service (DoS) condition. The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle E-Business Suite (Oracle Scheduler) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats