Junglewise Threat Intelligence

CVE-2026-60901: Oracle Project Intelligence takeover in Internal Operations

CVE-2026-60901 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Project Intelligence, a component of the Oracle E-Business Suite used by organizations to manage and analyze project-related data. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the Project Intelligence module. This could lead to the unauthorized disclosure of sensitive project data, modification of business records, or a complete disruption of the service.

Technical details

This vulnerability affects the Internal Operations component of Oracle Project Intelligence within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as easily exploitable, requiring only low-privileged user authentication and network access via HTTP. While the specific CWE is not identified in the advisory, the impact is rated as high for confidentiality, integrity, and availability, suggesting a significant authorization bypass or injection flaw that allows for a complete takeover of the affected component. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Project Intelligence (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats