Junglewise Threat Intelligence

CVE-2026-60904: Oracle E-Business Suite data compromise in Oracle Installed Base

CVE-2026-60904 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Installed Base. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Oracle Installed Base component of Oracle E-Business Suite, which is used by organizations to track and manage product lifecycles and customer assets. A low-privileged user can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the unauthorized viewing, modification, or deletion of critical asset records, potentially disrupting supply chain operations and compromising data integrity.

Technical details

This vulnerability affects the 'Create Item Instance' component within Oracle Installed Base (part of Oracle E-Business Suite). It is classified as an easily exploitable flaw that requires low-privileged authentication and network connectivity via HTTP. An attacker can bypass intended access controls to perform unauthorized creation, deletion, or modification of all data accessible to the Oracle Installed Base module. The exploit impacts both confidentiality and integrity but does not directly affect service availability. Affected versions range from 12.2.3 through 12.2.15.

Affected products

  • Oracle Corporation E-Business Suite (Oracle Installed Base) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats