Junglewise Threat Intelligence

CVE-2026-60871: Oracle Risk Management unauthorized data access in Internal Operations

CVE-2026-60871 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Risk Management, a tool used by businesses to manage financial and operational risks within the Oracle E-Business Suite. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could lead to the theft, deletion, or modification of critical financial records and risk management information, potentially disrupting corporate compliance and operations.

Technical details

This vulnerability affects the Internal Operations component of Oracle Risk Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an unauthorized data access/modification flaw that can be exploited by a low-privileged attacker with network access via HTTP. The exploit does not require user interaction and has a high impact on both confidentiality and integrity, allowing for the creation, deletion, or modification of all accessible data within the Risk Management module. The vulnerability was addressed in the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle Corporation Oracle Risk Management (Oracle E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: NVD published the CVE record.

References