Junglewise Threat Intelligence

CVE-2026-60931: Oracle E-Business Suite takeover in Public Sector Financials

CVE-2026-60931 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle Public Sector Financials. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Public Sector Financials, a component of the E-Business Suite used by government organizations to manage accounting and financial operations. A low-privileged user could exploit this flaw to gain full control over the application, potentially leading to the theft of sensitive financial data or disruption of critical public sector services. While the attack is difficult to execute, a successful breach would compromise the confidentiality and integrity of the entire system.

Technical details

This vulnerability affects the Internal Operations component of Oracle Public Sector Financials within the Oracle E-Business Suite. It is classified as a high-severity issue with a CVSS score of 7.5, characterized by a high attack complexity. An attacker requires network access via HTTP and low-level user privileges to exploit the flaw. Successful exploitation allows for a complete takeover of the Public Sector Financials product, impacting confidentiality, integrity, and availability. The vulnerability is addressed in the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle Public Sector Financials (E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.

References

Related threats