Junglewise Threat Intelligence

CVE-2026-60771: Oracle E-Business Suite data compromise in Complex Maintenance, Repair and Overhaul

CVE-2026-60771 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Complex Maintenance, Repair and Overhaul. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle's E-Business Suite module used for managing complex maintenance and repair operations. A user with low-level access to the system can exploit this flaw over the network to view, modify, or delete sensitive maintenance data. This could lead to significant data integrity issues or the unauthorized exposure of proprietary operational information.

Technical details

This vulnerability affects the Internal Operations component of the Oracle Complex Maintenance, Repair and Overhaul product within Oracle E-Business Suite. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can achieve unauthorized creation, deletion, or modification of all accessible data within the module, as well as complete read access to sensitive information. The vulnerability has a CVSS 3.1 base score of 8.1, impacting both confidentiality and integrity, though it does not directly impact service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle Complex Maintenance, Repair and Overhaul (E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats