Junglewise Threat Intelligence

CVE-2026-60768: Oracle Applications Framework data compromise in Graph / Charting

CVE-2026-60768 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Applications Framework. Vendors: Oracle.

Executive brief

A vulnerability exists in the Graph and Charting component of the Oracle Applications Framework, which is part of the Oracle E-Business Suite used for managing enterprise operations. An attacker with basic user access can exploit this flaw over the network to view, modify, or delete sensitive business data. This could lead to a significant breach of corporate information or the unauthorized alteration of critical financial and operational records.

Technical details

This vulnerability affects the Graph / Charting component of the Oracle Applications Framework within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the framework. Successful exploitation enables unauthorized creation, deletion, or modification of all accessible data, as well as complete unauthorized read access to critical information. The attack does not require user interaction. Organizations should refer to the Oracle July 2026 Critical Patch Update for remediation instructions.

Affected products

  • Oracle Applications Framework 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.

References

Related threats