Junglewise Threat Intelligence

CVE-2026-60918: Oracle Shipping Execution full compromise in Internal Operations

CVE-2026-60918 · Severity: high · CVSS 7.2 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Shipping Execution is a component of the Oracle E-Business Suite used to manage logistics and outbound shipping operations. A vulnerability in the Internal Operations component allows a high-privileged user to fully compromise the application. This could lead to unauthorized access to sensitive shipping data, disruption of logistics operations, and loss of data integrity.

Technical details

A vulnerability exists in the Internal Operations component of Oracle Shipping Execution (part of Oracle E-Business Suite). The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. While the specific CWE is not identified in the advisory, the impact is rated for full loss of Confidentiality, Integrity, and Availability (takeover). The vulnerability affects versions 12.2.12 through 12.2.15. Organizations should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Shipping Execution 12.2.12-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References