Junglewise Threat Intelligence

CVE-2026-60891: Oracle Work in Process Information Disclosure in Internal Operations

CVE-2026-60891 · Severity: low · CVSS 1.9 · Published 2026-07-21

Technologies: Oracle Work in Process. Vendors: Oracle.

Executive brief

Oracle Work in Process, a component of the Oracle E-Business Suite used for managing manufacturing operations, contains a security vulnerability in its Internal Operations component. A highly privileged attacker with existing access to the underlying server infrastructure could exploit this flaw to gain unauthorized read access to a limited amount of sensitive data. Because the attack requires high-level system access and faces significant technical hurdles, the overall risk to business operations is considered low.

Technical details

A vulnerability exists in the Internal Operations component of Oracle Work in Process (versions 12.2.3 through 12.2.15). The flaw is characterized by a high attack complexity, requiring a high-privileged attacker to have local logon access to the infrastructure where the software executes. Successful exploitation results in a low-impact breach of confidentiality, allowing unauthorized read access to a subset of data managed by the application. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Work in Process 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed

References

Related threats