Junglewise Threat Intelligence

CVE-2026-60937: Oracle Labor Distribution unauthorized data modification in Internal Operations

CVE-2026-60937 · Severity: low · CVSS 3.1 · Published 2026-07-21

Technologies: Oracle Labor Distribution. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Labor Distribution, a tool used by organizations to manage and allocate labor costs. An attacker with basic user access could potentially modify, add, or delete certain labor-related data. While the attack is difficult to perform, it could lead to unauthorized changes in financial or operational records.

Technical details

This vulnerability affects the Internal Operations component of Oracle Labor Distribution within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a low-severity issue because it requires a high level of complexity to exploit (AC:H) and requires the attacker to have at least low-level authenticated access (PR:L). An attacker with network access via HTTP can exploit this flaw to achieve unauthorized update, insert, or delete access to a subset of data within the Labor Distribution module. The impact is limited to integrity, with no reported impact on confidentiality or availability. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Labor Distribution (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle in the July 2026 CPU.
  • 2026-07-21: advisory: NVD published the CVE record.

References

Related threats