Junglewise Threat Intelligence

CVE-2026-60872: Oracle Order Management compromise in Product Diagnostic Tools

CVE-2026-60872 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Order Management. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Order Management, a component of the Oracle E-Business Suite used by organizations to manage sales and fulfillment processes. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the Order Management system. This could lead to the unauthorized access, modification, or deletion of sensitive customer orders and business data, potentially disrupting operations and compromising financial records.

Technical details

This vulnerability is located in the Product Diagnostic Tools component of Oracle Order Management within the Oracle E-Business Suite. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The vulnerability allows an attacker to achieve a complete compromise of the Order Management product, impacting confidentiality, integrity, and availability. While the specific vulnerability class (e.g., injection or broken access control) is not explicitly named in the advisory, the impact is rated as a full system takeover. The issue affects versions 12.2.3 through 12.2.15 and was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Order Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed: CVE-2026-60872 was published to the NVD.

References

Related threats