Junglewise Threat Intelligence

CVE-2026-60787: Oracle Receivables compromise in Internal Operations

CVE-2026-60787 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle Receivables. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Receivables, a key financial module within the Oracle E-Business Suite used for managing customer invoices and payments. A high-privileged attacker could exploit this flaw to gain full control over the Receivables system. This could lead to the unauthorized disclosure of sensitive financial data, modification of records, or disruption of accounting operations.

Technical details

This vulnerability affects the Internal Operations component of Oracle Receivables within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that can be triggered over the network via HTTP. While the exploit requires high privileges (PR:H), a successful attack results in a complete compromise of the Oracle Receivables product, impacting confidentiality, integrity, and availability. The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle Receivables 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats