Junglewise Threat Intelligence

CVE-2026-60788: Oracle Sales Offline data compromise in Internal Operations

CVE-2026-60788 · Severity: high · CVSS 8.3 · Published 2026-07-21

Technologies: Oracle Sales Offline. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Sales Offline, a tool used by sales teams to manage customer data and transactions without a constant internet connection. An attacker with basic user credentials could exploit this flaw to view, modify, or delete sensitive business data and disrupt the availability of the service. This could lead to significant data loss, unauthorized changes to sales records, and operational downtime.

Technical details

This vulnerability affects the Internal Operations component of Oracle Sales Offline within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that requires network access via HTTP and low-privileged user authentication. An attacker can exploit this to gain unauthorized access to critical data, including the ability to create, delete, or modify all accessible records. Additionally, the exploit can be used to cause a partial denial of service (DoS). The vulnerability is tracked as CVE-2026-60788 and has a CVSS 3.1 base score of 8.3. Patching information is typically found in the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle Corporation Sales Offline (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats