Junglewise Threat Intelligence

CVE-2026-60695: Oracle Enterprise Asset Management data compromise in Internal Operations

CVE-2026-60695 · Severity: medium · CVSS 5.9 · Published 2026-07-21

Technologies: Oracle Enterprise Asset Management. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Enterprise Asset Management, a tool used by organizations to manage physical assets and maintenance operations. A highly privileged attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify critical records. While the attack is difficult to perform and requires high-level access, it could lead to a significant breach of data integrity and confidentiality within the asset management system.

Technical details

A vulnerability in the Internal Operations component of Oracle Enterprise Asset Management (Oracle E-Business Suite) allows a high-privileged attacker with network access via HTTP to compromise the system. The vulnerability is characterized by high attack complexity, meaning successful exploitation relies on conditions beyond the attacker's direct control. If successfully exploited, an attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data accessible by the product. The issue affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Enterprise Asset Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats