Junglewise Threat Intelligence

CVE-2026-60825: Oracle iSupport takeover in Internal Operations

CVE-2026-60825 · Severity: medium · CVSS 6.6 · Published 2026-07-21

Technologies: Oracle Isupport. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle iSupport, a customer service and support module within the Oracle E-Business Suite. A highly privileged attacker could exploit this flaw to take full control of the iSupport component. While the attack is difficult to execute, a successful compromise could lead to the unauthorized access, modification, or deletion of sensitive support data and service disruption.

Technical details

This vulnerability affects the Internal Operations component of Oracle iSupport within Oracle E-Business Suite. It is classified as a difficult-to-exploit flaw that requires the attacker to have high-level privileges and network access via HTTP. If successfully exploited, the attacker can achieve a complete takeover of the Oracle iSupport product, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-60825 and was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle iSupport 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats