Junglewise Threat Intelligence

CVE-2026-60691: Oracle Content Manager unauthorized data access in Internal Operations

CVE-2026-60691 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle E-Business Suite. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability in the Internal Operations component of Oracle Content Manager allows an authorized user with low-level permissions to gain unauthorized access to sensitive data. An attacker could use this flaw to view, modify, or delete critical business information within the Oracle E-Business Suite. This could lead to significant data breaches or the corruption of essential corporate records.

Technical details

This vulnerability affects the Internal Operations component of Oracle Content Manager within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation grants the attacker unauthorized 'create, delete, or modify' access to critical data, as well as full read access to all data accessible by the Content Manager. The attack does not require user interaction and has a high impact on both confidentiality and integrity, though it does not directly impact service availability.

Affected products

  • Oracle Corporation Content Manager (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60691

References

Related threats