Junglewise Threat Intelligence

CVE-2026-60838: Oracle Price Protection unauthorized data modification in Internal Operations

CVE-2026-60838 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle Price Protection. Vendors: Oracle.

Executive brief

A security vulnerability exists in the Internal Operations component of Oracle Price Protection, a tool used by businesses to manage price changes and supplier claims. An attacker with basic user credentials can exploit this flaw over the network to modify, delete, or create critical business data. This could lead to significant financial inaccuracies, unauthorized data manipulation, and the exposure of sensitive pricing information.

Technical details

This vulnerability in Oracle Price Protection (part of Oracle E-Business Suite) affects the Internal Operations component. It is classified as an improper access control or data validation issue that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation enables the attacker to perform unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of data. The attack does not require user interaction and has a low complexity. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Price Protection (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: CVE-2026-60838 was publicly disclosed.

References

Related threats