Executive brief
A vulnerability exists in the Internal Operations component of Oracle Public Sector Financials, a suite used by government entities to manage budgeting and accounting. An attacker with low-level access to the network could exploit this flaw to take full control of the financial system. This could lead to the unauthorized disclosure of sensitive financial data, manipulation of records, or a complete disruption of financial operations.
Technical details
This vulnerability affects the Internal Operations component of Oracle Public Sector Financials within the Oracle E-Business Suite. It is classified as a high-complexity exploit (AC:H), meaning successful exploitation may require specific environmental conditions or timing. A low-privileged attacker with network access via HTTP can leverage this flaw to achieve a complete compromise of the application, impacting confidentiality, integrity, and availability. The vulnerability is present in versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Public Sector Financials (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60927 by Oracle