Junglewise Threat Intelligence

CVE-2026-60770: Oracle E-Business Suite takeover in Application Object Library

CVE-2026-60770 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle Application Object Library. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Application Object Library, a core component of the Oracle E-Business Suite used for managing application shared services. A low-privileged attacker could exploit this flaw to gain full control over the Application Object Library. This could lead to unauthorized access to sensitive business data, disruption of operations, and a total loss of system integrity.

Technical details

This vulnerability affects the Core component of the Oracle Application Object Library within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as difficult to exploit, requiring a low-privileged attacker to have network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle Application Object Library, impacting confidentiality, integrity, and availability. The attack complexity is high, suggesting specific conditions or timing may be required for a successful breach. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Application Object Library 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats