Junglewise Threat Intelligence

CVE-2026-60863: Oracle Advanced Pricing compromise in Pricing Installation

CVE-2026-60863 · Severity: high · CVSS 8.8 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

Oracle Advanced Pricing, a component of the Oracle E-Business Suite used for managing complex pricing logic and promotions, contains a high-severity vulnerability. An attacker with low-level user credentials can exploit this flaw over the network to gain full control of the pricing system. This could lead to unauthorized price changes, theft of sensitive financial data, or disruption of sales operations.

Technical details

This vulnerability exists in the Pricing Installation component of Oracle Advanced Pricing within Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation results in a complete takeover of the Oracle Advanced Pricing component, impacting confidentiality, integrity, and availability. The vulnerability is tracked as CVE-2026-60863 and was addressed in the Oracle Critical Patch Update for July 2026. Attacker interaction is not required, and the attack complexity is low.

Affected products

  • Oracle Corporation Oracle Advanced Pricing 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Published as part of Oracle Critical Patch Update
  • 2026-07-21: disclosed

References