Junglewise Threat Intelligence

CVE-2026-60868: Oracle Advanced Pricing unauthorized data access in Pricing Installation

CVE-2026-60868 · Severity: high · CVSS 7.1 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in the Pricing Installation component of Oracle Advanced Pricing, a tool used by businesses to manage complex product pricing and promotions. A low-privileged user could exploit this flaw to gain unauthorized access to sensitive pricing data or modify existing records. This could lead to the exposure of proprietary business strategies or unauthorized changes to product costs across the organization.

Technical details

This vulnerability affects the Pricing Installation component of Oracle Advanced Pricing versions 12.2.14 and 12.2.15. It is classified as difficult to exploit, requiring a low-privileged attacker to have network access via HTTP. The flaw allows for a 'scope change' (S:C), meaning an exploit can impact components beyond the immediate Oracle Advanced Pricing environment. Attackers can achieve unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation Advanced Pricing (Oracle E-Business Suite) 12.2.14, 12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.

References