Junglewise Threat Intelligence

CVE-2026-60907: Oracle E-Business Suite data manipulation in Oracle Installed Base

CVE-2026-60907 · Severity: medium · CVSS 5 · Published 2026-07-21

Technologies: Oracle Installed Base. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Oracle Installed Base component of the Oracle E-Business Suite, which is used by organizations to track and manage product lifecycles and customer assets. An attacker with basic user access could potentially view, modify, or delete certain business data, or cause minor service disruptions. While the impact is limited to a subset of data, it could affect the accuracy of asset records and operational reporting.

Technical details

This vulnerability affects the 'Create Item Instance' component within Oracle Installed Base (part of Oracle E-Business Suite). It is classified as difficult to exploit (High Attack Complexity) and requires the attacker to have low-level authenticated access to the network via HTTP. Successful exploitation allows an attacker to perform unauthorized read, update, insert, or delete operations on a subset of data accessible to the component. Additionally, an attacker can cause a partial denial of service (DoS). The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation E-Business Suite (Oracle Installed Base) 12.2.4-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats