Junglewise Threat Intelligence

CVE-2026-60772: Oracle Financials Common Modules data manipulation in Common Components

CVE-2026-60772 · Severity: high · CVSS 7.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Financials Common Modules, a component of the Oracle E-Business Suite used for managing corporate financial data. An attacker with basic user credentials can exploit this flaw over the network to modify, delete, or create critical financial records. This could lead to significant data integrity issues, unauthorized financial transactions, or the exposure of sensitive business information.

Technical details

This vulnerability affects the Common Components of Oracle Financials Common Modules within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation enables unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of the module's data. The attack does not require user interaction. Security updates are typically provided via the Oracle Critical Patch Update (CPU) program.

Affected products

  • Oracle Financials Common Modules 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats