Executive brief
A vulnerability exists in the Oracle Applications Framework, a core component of the Oracle E-Business Suite used for building and deploying web-based applications. An attacker with low-level user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft of critical information or the unauthorized modification and deletion of records within the system.
Technical details
A vulnerability in the Search Bean (including Advanced Search) component of the Oracle Applications Framework allows for unauthorized data access and manipulation. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to achieve unauthorized read access to all data accessible through the framework, as well as unauthorized update, insert, or delete capabilities for a subset of that data. The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Applications Framework 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60774
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released