Junglewise Threat Intelligence

CVE-2026-60697: Oracle Site Hub unauthorized data access in Site Hierarchy Flows

CVE-2026-60697 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Site Hub, a component of the Oracle E-Business Suite used for managing centralized site and location data. An attacker with low-level user credentials can exploit this flaw over the network to view, modify, or delete certain business data. Additionally, an exploit could cause partial service disruptions, potentially impacting operational efficiency and data integrity.

Technical details

A vulnerability in the Site Hierarchy Flows component of Oracle Site Hub (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to read, update, insert, or delete a subset of data within Site Hub, and can also result in a partial denial of service (DoS). The affected versions range from 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Site Hub 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References