Junglewise Threat Intelligence

CVE-2026-60694: Oracle Enterprise Asset Management unauthorized data access in Internal Operations

CVE-2026-60694 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Enterprise Asset Management. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Enterprise Asset Management, a tool used by organizations to manage physical assets and maintenance operations. An attacker with basic user access could trick another user into performing an action that allows the attacker to view, modify, or delete certain business data. While the direct impact is within the asset management system, the breach could potentially spread to affect other connected Oracle business systems.

Technical details

This vulnerability affects the Internal Operations component of Oracle Enterprise Asset Management within Oracle E-Business Suite. It is classified as a scope-changing vulnerability, likely indicating a Cross-Site Scripting (XSS) or similar injection flaw that allows an attacker to impact components beyond the immediate application. An attacker requires low-level privileges and network access via HTTP, but the exploit is dependent on human interaction from a victim (User Interaction: Required). Successful exploitation enables unauthorized read, update, insert, or delete access to a subset of the application's data. The issue affects versions 12.2.3 through 12.2.15 and was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Enterprise Asset Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed

References

Related threats