Junglewise Threat Intelligence

CVE-2026-60807: Oracle Bills of Material takeover in Internal Operations

CVE-2026-60807 · Severity: high · CVSS 8 · Published 2026-07-21

Technologies: Oracle Bills of Material. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle Bills of Material, a component of the Oracle E-Business Suite used for managing manufacturing product structures and parts lists. An attacker with basic user access could potentially take full control of the system if they can trick another user into performing a specific action. This could lead to the unauthorized viewing or modification of sensitive manufacturing data and disruption of business operations.

Technical details

This vulnerability affects the Internal Operations component of Oracle Bills of Material within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the application. The attack requires human interaction (UI:R) from a victim, suggesting a Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) style vector that leads to a complete compromise of Confidentiality, Integrity, and Availability. Successful exploitation can result in a total takeover of the affected component. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Bills of Material 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60807 by Oracle
  • 2026-07-21: advisory: NVD dataset inclusion and Oracle July 2026 CPU release

References

Related threats