Junglewise Threat Intelligence

CVE-2026-60799: Oracle Compensation Workbench unauthorized data access in E-Business Suite

CVE-2026-60799 · Severity: high · CVSS 7.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Compensation Workbench, a tool within the Oracle E-Business Suite used by organizations to manage employee salaries and incentives. An attacker with basic user access can exploit this flaw over the network to view sensitive compensation data or modify certain records. This could lead to the exposure of confidential payroll information or unauthorized changes to financial data.

Technical details

A vulnerability in the Compensation Workbench component of Oracle E-Business Suite (versions 12.2.3 through 12.2.15) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation can result in the compromise of confidentiality for all accessible data and partial loss of integrity through unauthorized updates, inserts, or deletions. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Compensation Workbench 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats