Junglewise Threat Intelligence

CVE-2026-60826: Oracle iSupport takeover in Internal Operations

CVE-2026-60826 · Severity: medium · CVSS 6.6 · Published 2026-07-21

Technologies: Oracle Isupport. Vendors: Oracle.

Executive brief

Oracle iSupport, a customer service and support module within the Oracle E-Business Suite, contains a vulnerability in its Internal Operations component. A high-privileged attacker could exploit this flaw to gain full control over the iSupport system. Such an attack could lead to a total loss of confidentiality, integrity, and service availability for the support platform.

Technical details

This vulnerability affects Oracle iSupport versions 12.2.3 through 12.2.15 within the Oracle E-Business Suite. The flaw exists in the Internal Operations component and is characterized by a high attack complexity, requiring the attacker to possess high-level administrative privileges. Exploitation occurs over the network via HTTP and does not require user interaction. A successful exploit allows for a complete takeover of the iSupport product, impacting confidentiality, integrity, and availability. Oracle has addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle iSupport 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats