Junglewise Threat Intelligence

CVE-2026-60857: Oracle Contracts Integration data compromise in Internal Operations

CVE-2026-60857 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Contracts Integration. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Contracts Integration, a tool used within the Oracle E-Business Suite to manage business agreements. An attacker with basic user credentials can exploit this flaw over the network to gain full access to contract data. This could lead to the unauthorized viewing, modification, or deletion of sensitive corporate contracts and legal documents.

Technical details

A vulnerability in the Internal Operations component of Oracle Contracts Integration (versions 12.2.3 through 12.2.15) allows for unauthorized data access and modification. The flaw is categorized as easily exploitable and requires only low-privileged user authentication. An attacker can reach the vulnerable component via HTTP over the network. Successful exploitation enables the attacker to create, delete, or modify all accessible data within the Contracts Integration module, as well as gain complete read access to sensitive information. The vulnerability impacts confidentiality and integrity but does not affect service availability.

Affected products

  • Oracle Corporation Oracle Contracts Integration 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
  • 2026-07-21: disclosed: CVE-2026-60857 was published to the NVD.

References

Related threats