Junglewise Threat Intelligence

CVE-2026-60923: Oracle Capacity unauthorized data access in Internal Operations

CVE-2026-60923 · Severity: high · CVSS 7.7 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

Oracle Capacity, a component of the Oracle E-Business Suite used for manufacturing and resource planning, contains a security vulnerability in its Internal Operations component. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This breach could lead to the exposure of critical organizational information and potentially impact other integrated Oracle products.

Technical details

A vulnerability exists in the Internal Operations component of Oracle Capacity (part of Oracle E-Business Suite) affecting versions 12.2.3 through 12.2.15. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation results in a scope change (S:C), meaning the impact can extend beyond Oracle Capacity to other products within the suite. The primary impact is a high loss of confidentiality, allowing unauthorized access to all data accessible by the Oracle Capacity component. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation Oracle Capacity 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.

References