Junglewise Threat Intelligence

CVE-2026-60777: Oracle Application Object Library unauthorized data access in Core component

CVE-2026-60777 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle Application Object Library. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Core component of the Oracle Application Object Library, which is a foundational part of the Oracle E-Business Suite used for managing business applications. An attacker with low-level user credentials could exploit this flaw over the network to view, modify, or delete sensitive business data. Additionally, an exploit could cause a partial service disruption, impacting the availability of business operations.

Technical details

This vulnerability affects the Core component of the Oracle Application Object Library within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged user authentication and network access via HTTP. Successful exploitation allows an attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of data accessible to the library. Furthermore, the vulnerability can be leveraged to cause a partial denial of service (DoS). The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Oracle Application Object Library 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: CVE-2026-60777 was published to the NVD.

References

Related threats