Junglewise Threat Intelligence

CVE-2026-60738: Oracle E-Business Suite compromise in Oracle Installed Base

CVE-2026-60738 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Installed Base. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Oracle Installed Base component of the Oracle E-Business Suite, which is used by organizations to track and manage product lifecycles and customer assets. A low-privileged user with network access can exploit this flaw to gain full control over the Installed Base system. This could lead to the unauthorized viewing, modification, or deletion of sensitive asset data and disrupt business operations.

Technical details

This vulnerability affects the 'Create Item Instance' component of Oracle Installed Base within Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation can result in a complete takeover of the Oracle Installed Base module, impacting confidentiality, integrity, and availability. The attack does not require user interaction. While the specific vulnerability class (e.g., SQLi, broken access control) is not explicitly named in the advisory, the impact indicates a significant authorization or input validation failure. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle Corporation Oracle Installed Base 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: NVD and Oracle published the vulnerability details.

References

Related threats