Junglewise Threat Intelligence

CVE-2026-60706: Oracle Process Manufacturing Inventory data compromise in Internal Operations

CVE-2026-60706 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Inventory, a tool used by businesses to manage manufacturing stocks and production flows. An attacker with basic user credentials can exploit this flaw over the network to gain full access to sensitive inventory data. This could lead to the unauthorized viewing, modification, or deletion of critical business records, potentially disrupting supply chains or compromising financial integrity.

Technical details

This vulnerability affects the Internal Operations component of Oracle Process Manufacturing Inventory within the Oracle E-Business Suite. It is classified as an improper access control or similar flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation enables the attacker to achieve unauthorized creation, deletion, or modification of all accessible data, as well as complete read access to sensitive information. The vulnerability is easily exploitable and does not require user interaction. Affected versions range from 12.2.3 through 12.2.15, and users are advised to apply the relevant Oracle Critical Patch Update.

Affected products

  • Oracle Process Manufacturing Inventory 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD record published

References