Junglewise Threat Intelligence

CVE-2026-60859: Oracle Quoting compromise in Internal Operations

CVE-2026-60859 · Severity: high · CVSS 7.5 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in Oracle Quoting, a component of the Oracle E-Business Suite used by organizations to manage sales quotes and proposals. A low-privileged attacker could exploit this flaw to gain full control over the Quoting module. This could lead to the unauthorized modification of sales data, exposure of sensitive customer pricing, or disruption of the quoting process.

Technical details

This vulnerability affects the Internal Operations component of Oracle Quoting within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as difficult to exploit (High Attack Complexity), requiring a low-privileged attacker to have network access via HTTP. Successful exploitation allows for a complete compromise of the Oracle Quoting component, impacting confidentiality, integrity, and availability. While the specific vulnerability class (e.g., injection or broken access control) is not explicitly detailed in the advisory, the impact is listed as a full 'takeover' of the product. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle Quoting 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-60859 by Oracle

References