Junglewise Threat Intelligence

CVE-2026-60930: Oracle Public Sector Financials information disclosure in Internal Operations

CVE-2026-60930 · Severity: low · CVSS 3.1 · Published 2026-07-21

Technologies: Oracle Public Sector Financials. Vendors: Oracle.

Executive brief

Oracle Public Sector Financials, a component of the E-Business Suite used by government organizations for financial management, contains a security vulnerability in its Internal Operations component. An attacker with existing low-level access to the network could potentially view sensitive financial data they are not authorized to see. While the risk is limited to unauthorized data reading and the attack is difficult to perform, it could lead to the exposure of internal organizational information.

Technical details

This vulnerability affects the Internal Operations component of Oracle Public Sector Financials within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a low-severity information disclosure bug that is difficult to exploit (High Attack Complexity). An attacker requires network access via HTTP and low-privileged credentials to successfully execute the attack. If successful, the attacker can obtain unauthorized read access to a limited subset of data managed by the Public Sector Financials product. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Public Sector Financials 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed

References

Related threats