Junglewise Threat Intelligence

CVE-2026-60804: Oracle E-Business Intelligence unauthorized data modification in Definition

CVE-2026-60804 · Severity: low · CVSS 2 · Published 2026-07-21

Technologies: Oracle E-Business Intelligence. Vendors: Oracle.

Executive brief

A vulnerability exists in the Definition component of Oracle E-Business Intelligence, a tool used for business data analysis and reporting. A highly privileged attacker could potentially modify, insert, or delete certain business data, though this requires a legitimate user to perform a specific action. The risk is considered low because the attack is difficult to execute and requires significant existing access.

Technical details

This vulnerability affects the Definition component of Oracle E-Business Intelligence versions 12.2.3 through 12.2.15. It is classified as a low-impact integrity issue where a high-privileged attacker with network access via HTTP can perform unauthorized updates, insertions, or deletions of data. The attack is characterized by high complexity (AC:H) and requires human interaction (UI:R) from a person other than the attacker. The vulnerability does not impact data confidentiality or service availability. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle E-Business Intelligence 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats