Junglewise Threat Intelligence

CVE-2026-60775: Oracle E-Business Suite compromise of Pasta in Internal Operations

CVE-2026-60775 · Severity: medium · CVSS 6.7 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Pasta component of Oracle E-Business Suite, which is used for printing and document formatting. An attacker who already has high-level administrative access to the underlying server can exploit this flaw to take full control of the Pasta service. This could lead to the unauthorized access, modification, or deletion of sensitive business documents and reports.

Technical details

This vulnerability affects the Internal Operations component of Oracle Pasta in Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an 'easily exploitable' flaw that requires the attacker to have local logon access to the infrastructure where Pasta executes. The attack requires high privileges (PR:H), meaning the attacker must already possess administrative or near-administrative rights on the host system. Successful exploitation results in a complete compromise of the Pasta product, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle E-Business Suite Pasta 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References