Junglewise Threat Intelligence

CVE-2026-60842: Oracle Knowledge Management cross-site vulnerability in Search component

CVE-2026-60842 · Severity: medium · CVSS 6.1 · Published 2026-07-21

Technologies: Oracle Knowledge Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the Search component of Oracle Knowledge Management, a tool used by businesses to manage and share corporate information. An attacker could trick a user into performing an action that allows the attacker to view, modify, or delete certain business data. This could lead to unauthorized data changes or the exposure of sensitive internal information.

Technical details

This vulnerability affects the Search component of Oracle Knowledge Management within Oracle E-Business Suite versions 12.2.5 through 12.2.15. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The exploit requires human interaction from a person other than the attacker (UI:R) and results in a scope change (S:C), suggesting a Cross-Site Scripting (XSS) or similar injection-based vulnerability. Successful exploitation can result in unauthorized read, update, insert, or delete access to a subset of data accessible to the Knowledge Management product.

Affected products

  • Oracle Knowledge Management (E-Business Suite) 12.2.5-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60842
  • 2026-07-21: advisory: Oracle Critical Patch Update (CPU) July 2026 released

References

Related threats