Junglewise Threat Intelligence

CVE-2026-60840: Oracle Demand Signal Repository SQL injection in Internal Operations

CVE-2026-60840 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Demand Signal Repository. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Demand Signal Repository, a tool used by businesses to analyze retail and supply chain data. An attacker with basic user credentials can exploit this flaw over the network to gain full access to sensitive repository data. This could lead to the unauthorized viewing, modification, or deletion of critical business information, potentially disrupting supply chain operations and compromising data integrity.

Technical details

This vulnerability affects the Internal Operations component of Oracle Demand Signal Repository within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via SQL to compromise the system. Successful exploitation grants the attacker unauthorized 'create, delete, or modification' access as well as 'read' access to all data accessible by the repository. The vulnerability has a CVSS 3.1 base score of 8.1, impacting confidentiality and integrity but not availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Demand Signal Repository 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD record published

References

Related threats