Junglewise Threat Intelligence

CVE-2026-60888: Oracle Work in Process confidentiality breach in Internal Operations

CVE-2026-60888 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle Work in Process. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Work in Process, a module within the Oracle E-Business Suite used for managing manufacturing floor operations. An attacker with basic user access could potentially gain unauthorized access to sensitive business data. This could lead to the exposure of proprietary manufacturing processes or critical operational information.

Technical details

This vulnerability affects the Internal Operations component of Oracle Work in Process (Oracle E-Business Suite). It is characterized by a high attack complexity, requiring specific conditions to be met for successful exploitation. A low-privileged attacker with network access via HTTP can exploit this flaw to bypass confidentiality controls. Successful exploitation results in unauthorized access to critical data or a complete breach of all data accessible to the Work in Process module. The vulnerability is present in versions 12.2.3 through 12.2.15 and was addressed in the July 2026 Oracle Critical Patch Update.

Affected products

  • Oracle Work in Process 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats