Junglewise Threat Intelligence

CVE-2026-60778: Oracle E-Business Suite data compromise in Oracle Payments File Transmission

CVE-2026-60778 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Payments. Vendors: Oracle.

Executive brief

A security vulnerability exists in the Oracle Payments module of the Oracle E-Business Suite, which handles financial transactions and electronic fund transfers. An authorized user with low-level permissions could exploit this flaw to gain full access to sensitive payment data, allowing them to view, modify, or delete critical financial records. This could lead to significant financial data breaches or unauthorized changes to corporate payment processing.

Technical details

This vulnerability affects the File Transmission component of Oracle Payments within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires network access via HTTP and low-privileged user authentication. An attacker can leverage this vulnerability to achieve unauthorized creation, deletion, or modification of critical data, as well as complete read access to all data managed by the Oracle Payments module. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle E-Business Suite (Oracle Payments) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60778
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats