Junglewise Threat Intelligence

CVE-2026-60802: Oracle E-Business Intelligence data manipulation in Internal Operations

CVE-2026-60802 · Severity: medium · CVSS 6.1 · Published 2026-07-21

Technologies: Oracle E-Business Intelligence. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle E-Business Intelligence, a tool used by organizations for business data analysis and reporting. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to unauthorized changes in business records or the exposure of confidential internal information.

Technical details

A vulnerability in the Internal Operations component of Oracle E-Business Intelligence (versions 12.2.3 through 12.2.15) allows an unauthenticated remote attacker to impact the confidentiality and integrity of the system. The attack is carried out via HTTP and requires human interaction from a person other than the attacker (User Interaction: Required). The vulnerability features a 'Scope Change,' meaning a successful exploit can impact components or products beyond the immediate E-Business Intelligence environment. Attackers can achieve unauthorized read, update, insert, or delete access to a subset of accessible data. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle E-Business Intelligence 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats