Junglewise Threat Intelligence

CVE-2026-60800: Oracle Compensation Workbench unauthorized data access in E-Business Suite

CVE-2026-60800 · Severity: high · CVSS 7.1 · Published 2026-07-21

Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Oracle Compensation Workbench, a component of the Oracle E-Business Suite used by organizations to manage employee compensation and benefits. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive compensation data. This could lead to the exposure of confidential payroll information or unauthorized changes to certain records within the system.

Technical details

This vulnerability affects the Compensation Workbench component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an improper access control or similar flaw that allows a low-privileged attacker (authenticated user) to access or modify data they should not have permissions for. The attack vector is remote via HTTP, requiring no user interaction. Exploitation can lead to a high impact on confidentiality (unauthorized access to all accessible data) and a low impact on integrity (unauthorized update, insert, or delete access to some data). The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Compensation Workbench 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: CVE-2026-60800 was publicly released.

References

Related threats