Junglewise Threat Intelligence

CVE-2026-60848: Oracle Project Contracts data compromise in Internal Operations

CVE-2026-60848 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Project Contracts. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Project Contracts, a component of the Oracle E-Business Suite used by organizations to manage complex contract lifecycles and compliance. A low-privileged user can exploit this flaw over the network to gain unauthorized access to sensitive contract data. This could result in the theft, modification, or deletion of critical business records, potentially impacting financial integrity and regulatory compliance.

Technical details

This vulnerability affects the Internal Operations component of Oracle Project Contracts within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires only low-level user privileges and network connectivity via HTTP. An attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as complete read access to all data within the Project Contracts module. The vulnerability has significant impacts on confidentiality and integrity but does not affect service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Project Contracts 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats