Junglewise Threat Intelligence

CVE-2026-60708: Oracle Process Manufacturing Financials unauthorized data access in Internal Operations

CVE-2026-60708 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Financials, a tool used by businesses to manage manufacturing costs and financial reporting. An attacker with basic user access can exploit this flaw over the network to view, modify, or delete sensitive financial data. This could lead to significant data breaches, unauthorized financial changes, and loss of data integrity within the organization's enterprise resource planning (ERP) system.

Technical details

This vulnerability affects the Internal Operations component of Oracle Process Manufacturing Financials within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that can be triggered by a low-privileged attacker with network access via HTTP. Successful exploitation allows for unauthorized creation, deletion, or modification of critical data, as well as full read access to all data accessible by the component. The attack does not require user interaction and has a high impact on both confidentiality and integrity, though it does not directly impact service availability.

Affected products

  • Oracle Corporation Process Manufacturing Financials (E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle in the July 2026 Critical Patch Update

References