Junglewise Threat Intelligence

CVE-2026-60744: Oracle Cost Management unauthorized data access in Internal Operations

CVE-2026-60744 · Severity: medium · CVSS 6.8 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in Oracle Cost Management, a component of the Oracle E-Business Suite used by organizations to track and manage manufacturing and inventory costs. An attacker with basic user access could potentially view, modify, or delete sensitive financial and operational data. While the attack is complex to execute, a successful breach could compromise the integrity and confidentiality of the entire cost management system.

Technical details

This vulnerability affects the Internal Operations component of Oracle Cost Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a high-complexity attack (AC:H) that requires the attacker to have low-level privileges (PR:L) and network access via HTTP. If successfully exploited, the attacker can achieve unauthorized access to, or modification of, all data accessible to the Oracle Cost Management product. The vulnerability impacts both confidentiality and integrity but does not affect system availability. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation Oracle Cost Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed: CVE-2026-60744 was published to the NVD.

References