Junglewise Threat Intelligence

CVE-2026-60837: Oracle Price Protection data compromise in Internal Operations

CVE-2026-60837 · Severity: high · CVSS 8.4 · Published 2026-07-21

Technologies: Oracle Price Protection. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability in the Internal Operations component of Oracle Price Protection could allow a user with low-level access to the system to gain full control over the application's data. This could lead to the unauthorized viewing, modification, or deletion of sensitive financial and pricing information. Because of the way the software is integrated, an attacker might also be able to impact other connected Oracle E-Business Suite products.

Technical details

This vulnerability exists in the Internal Operations component of Oracle Price Protection within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires the attacker to have local logon credentials to the infrastructure where the software executes (AV:L). The vulnerability is notable for a 'scope change' (S:C), meaning an exploit can impact components beyond the immediate security scope of Oracle Price Protection. Attackers with low privileges can achieve high confidentiality and integrity impacts, potentially gaining full access to or control over critical application data. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle Price Protection (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle Corporation
  • 2026-07-21: advisory: NVD entry published

References

Related threats