Junglewise Threat Intelligence

CVE-2026-60824: Oracle iSupport unauthorized data access in Internal Operations

CVE-2026-60824 · Severity: high · CVSS 7.7 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in Oracle iSupport, a customer service and support module within the Oracle E-Business Suite. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. Because the vulnerability allows for a 'scope change,' an attacker may be able to access information beyond just the iSupport module, potentially impacting other integrated business systems and data.

Technical details

This vulnerability affects the Internal Operations component of Oracle iSupport within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an information disclosure flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. The vulnerability is notable for a 'scope change' (Status: C in CVSS), meaning a successful exploit can impact resources managed by other security authorities beyond Oracle iSupport. Successful exploitation results in high confidentiality impacts, potentially granting complete access to all data accessible via the iSupport interface. The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation iSupport (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Published as part of Oracle Critical Patch Update
  • 2026-07-21: disclosed

References