Junglewise Threat Intelligence

CVE-2026-60929: Oracle Public Sector Financials data manipulation in Internal Operations

CVE-2026-60929 · Severity: low · CVSS 3.1 · Published 2026-07-21

Technologies: Oracle Public Sector Financials. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in Oracle Public Sector Financials, a suite of tools used by government organizations to manage budgeting and accounting. An attacker with basic user credentials could potentially modify, add, or delete certain financial data. While the attack is difficult to perform, it could lead to unauthorized changes in official financial records.

Technical details

This vulnerability is located in the Internal Operations component of Oracle Public Sector Financials within the Oracle E-Business Suite. It is classified as an integrity-impacting flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Exploitation is considered difficult (High Attack Complexity), but if successful, it enables the unauthorized update, insertion, or deletion of specific data accessible to the product. The vulnerability affects supported versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Public Sector Financials 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats