Junglewise Threat Intelligence

CVE-2026-60810: Oracle Supply Chain Trading Connector data compromise in Collaboration History

CVE-2026-60810 · Severity: high · CVSS 8.2 · Published 2026-07-21

Technologies: Oracle Supply Chain Trading Connector. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Supply Chain Trading Connector, a component of the Oracle E-Business Suite used to manage business-to-business transactions and collaboration history. An attacker can exploit this flaw over the network without needing a username or password. If successful, the attacker could gain unauthorized access to sensitive business data and potentially modify or delete records, impacting the integrity of supply chain operations.

Technical details

This vulnerability affects the Collaboration History component of the Oracle Supply Chain Trading Connector within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit can lead to unauthorized access to all accessible data (High Confidentiality impact) and unauthorized update, insert, or delete capabilities for some data (Low Integrity impact). The attack does not require user interaction or elevated privileges. The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Supply Chain Trading Connector 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: NVD published the CVE record.

References

Related threats