Junglewise Threat Intelligence

CVE-2026-60789: Oracle Sales Offline full compromise in Internal Operations

CVE-2026-60789 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Sales Offline. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Sales Offline, a tool used by sales teams to manage customer data and sales activities without a constant internet connection. An attacker with basic user access can exploit this flaw over the network to take full control of the application. This could lead to the theft of sensitive sales data, unauthorized modification of business records, or a complete disruption of sales operations.

Technical details

This vulnerability affects the Internal Operations component of Oracle Sales Offline within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation can result in a complete takeover of the Oracle Sales Offline instance, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-60789 and has a CVSS 3.1 base score of 8.8. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Sales Offline (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats