Junglewise Threat Intelligence

CVE-2026-60940: Oracle Service Contracts data compromise in Internal Operations

CVE-2026-60940 · Severity: medium · CVSS 5.7 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in Oracle Service Contracts, a component of the Oracle E-Business Suite used for managing service-level agreements and warranties. A highly privileged attacker could potentially gain unauthorized access to view, modify, or delete critical contract data. Exploiting this issue is considered difficult as it requires the attacker to trick another user into performing a specific action.

Technical details

This vulnerability affects the Internal Operations component of Oracle Service Contracts within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a medium-severity issue with a CVSS score of 5.7, characterized by high complexity (AC:H) and the requirement for a high-privileged attacker (PR:H). The attack vector is network-based via HTTP, and successful exploitation requires user interaction (UI:R) from someone other than the attacker. If successful, an attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as complete read access to all data within the Service Contracts module. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Oracle Service Contracts 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: CVE-2026-60940 was published to the NVD.

References