Executive brief
A vulnerability exists in the Oracle Application Object Library, a core component of the Oracle E-Business Suite used for managing application data and security. A highly privileged attacker with existing access to the underlying server infrastructure could exploit this flaw to take full control of the library. This could lead to a total loss of confidentiality, integrity, and availability for the affected business applications and their data.
Technical details
A vulnerability in the AOL Generic Loader component of the Oracle Application Object Library (part of Oracle E-Business Suite) allows for a complete compromise of the component. The exploit requires the attacker to have high privileges and local logon access to the infrastructure where the library executes. Successful exploitation results in a total impact on confidentiality, integrity, and availability (takeover of the library). The vulnerability affects versions 12.2.3 through 12.2.15 and was addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Application Object Library (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: CVE-2026-60776 was published to the NVD.