Executive brief
A vulnerability exists in Oracle Field Service, a component of the Oracle E-Business Suite used to manage field-based workforces and service operations. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft of critical information or the unauthorized modification and deletion of records within the system.
Technical details
This vulnerability affects the Internal Operations component of Oracle Field Service within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can leverage this vulnerability to achieve high confidentiality impacts, gaining unauthorized access to all data accessible by the component. Additionally, it allows for limited integrity impacts, enabling the unauthorized insertion, updating, or deletion of some data. The vulnerability does not impact service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Field Service 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60739 by Oracle.
- 2026-07-21: advisory: NVD entry published.