Junglewise Threat Intelligence

CVE-2026-60854: Oracle Quality vulnerability in Internal Operations

CVE-2026-60854 · Severity: high · CVSS 8.2 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

Oracle Quality, a component of the Oracle E-Business Suite used for managing enterprise quality standards, contains a vulnerability in its Internal Operations component. A high-privileged user can exploit this flaw over the network to gain unauthorized access to sensitive data or modify records. This could lead to a significant breach of corporate data integrity and potential disruption of quality management processes.

Technical details

This vulnerability exists in the Internal Operations component of Oracle Quality within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as easily exploitable, requiring network access via HTTP and high-level administrative privileges. A successful exploit results in a 'scope change' (S:C), meaning the attacker can impact components beyond Oracle Quality itself. Impact includes unauthorized read access to all data, unauthorized modification or deletion of some data, and the ability to cause a partial denial of service. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle Quality 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle and NVD publication.
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.

References