Junglewise Threat Intelligence

CVE-2026-60741: Oracle Cost Management data compromise in Internal Operations

CVE-2026-60741 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Cost Management, a component of the Oracle E-Business Suite used for tracking and managing manufacturing and supply chain costs, contains a security vulnerability in its Internal Operations component. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive financial data. This could result in the unauthorized viewing, modification, or deletion of critical business records, potentially impacting financial reporting and operational integrity.

Technical details

A vulnerability exists in the Internal Operations component of Oracle Cost Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is classified as easily exploitable and requires low-privileged user authentication to execute via HTTP. Successful exploitation allows an attacker to achieve high confidentiality and integrity impacts, enabling unauthorized creation, deletion, or modification of all data accessible to the Cost Management module. The vulnerability does not impact system availability (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation.

Affected products

  • Oracle Cost Management (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and CPU advisory.
  • 2026-07-21: advisory

References