Junglewise Threat Intelligence

CVE-2026-60911: Oracle Property Manager data manipulation in Internal Operations

CVE-2026-60911 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Property Manager. Vendors: Oracle.

Executive brief

Oracle Property Manager, a component of the Oracle E-Business Suite used for managing real estate portfolios and lease agreements, contains a security vulnerability. A low-privileged user could potentially view, modify, or delete certain property-related data if they can trick an authorized user into performing a specific action. This could lead to unauthorized changes in financial or property records and may impact other integrated Oracle business applications.

Technical details

A vulnerability exists in the Internal Operations component of Oracle Property Manager (versions 12.2.3 through 12.2.15). The flaw is categorized by a scope change (S:C), suggesting it may be a Cross-Site Scripting (XSS) or similar injection vulnerability that allows an attacker to impact other products beyond the initial component. An attacker with low privileges can exploit this over the network via HTTP, though success requires interaction from a victim (UI:R). If successful, the attacker can gain unauthorized read, update, insert, or delete access to a subset of data within the Property Manager. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Property Manager 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60911
  • 2026-07-21: advisory: Included in Oracle July 2026 Critical Patch Update

References

Related threats