Junglewise Threat Intelligence

CVE-2026-60855: Oracle Quality compromise in E-Business Suite Internal Operations

CVE-2026-60855 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle Quality. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Quality, a component of the Oracle E-Business Suite used for enterprise quality management and data collection. A remote attacker with basic user credentials could exploit this flaw to gain full control over the Oracle Quality system. This could lead to the unauthorized modification of quality records, theft of sensitive operational data, or disruption of quality control processes.

Technical details

This vulnerability affects the Internal Operations component of Oracle Quality within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a high-complexity exploit (AC:H), meaning successful exploitation may rely on specific environmental conditions or configurations. An attacker requires low-privileged user credentials (PR:L) and network access via HTTP to execute the attack. Successful exploitation results in a complete compromise of Confidentiality, Integrity, and Availability (C:H/I:H/A:H), effectively allowing a takeover of the Oracle Quality product. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Quality 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats