Junglewise Threat Intelligence

CVE-2026-60844: Oracle E-Business Suite Customer Support data manipulation in Update Service Request

CVE-2026-60844 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Customer Support module of the Oracle E-Business Suite, specifically within the Update Service Request component. This flaw allows an authorized user with low-level permissions to gain unauthorized access to sensitive customer support data. An attacker could potentially view, modify, or delete critical support information, leading to significant data integrity and confidentiality risks for the organization.

Technical details

A vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (specifically the Update Service Request component) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation grants the attacker the ability to create, delete, or modify critical data, as well as gain complete read access to all data accessible within the Oracle Customer Support module. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Customer Support 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References