Junglewise Threat Intelligence

CVE-2026-60795: Oracle iSetup data compromise in General Ledger Update Transform

CVE-2026-60795 · Severity: medium · CVSS 6.8 · Published 2026-07-21

Technologies: Oracle Isetup. Vendors: Oracle.

Executive brief

Oracle iSetup, a tool used for migrating and configuring data within the Oracle E-Business Suite, contains a security vulnerability in its reporting and ledger update components. An attacker with basic user credentials could exploit this flaw to gain unauthorized access to sensitive financial data or modify critical business records. While the attack is complex to execute, a successful breach could compromise the integrity and confidentiality of the entire iSetup environment.

Technical details

This vulnerability affects the General Ledger Update Transform and Reports components of Oracle iSetup within Oracle E-Business Suite. It is classified as a medium-severity flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. The attack is considered difficult to exploit (High Attack Complexity), but if successful, it grants the attacker unauthorized creation, deletion, or modification access to all data accessible by iSetup, as well as full read access to that data. The vulnerability impacts confidentiality and integrity but does not affect service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle iSetup (E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.

References

Related threats