Junglewise Threat Intelligence

CVE-2026-60941: Oracle E-Business Suite data compromise in Service Fulfillment Manager

CVE-2026-60941 · Severity: high · CVSS 8.7 · Published 2026-07-21

Technologies: Oracle E-Business Suite Service Fulfillment Manager. Vendors: Oracle.

Executive brief

A vulnerability exists in the Fulfillment Engine component of Oracle E-Business Suite's Service Fulfillment Manager. This tool is used by organizations to manage and automate the delivery of services and products. A successful exploit could allow an attacker to gain full access to sensitive business data, potentially leading to unauthorized data modification or theft that could impact other integrated business systems.

Technical details

A vulnerability in the Fulfillment Engine component of Oracle Service Fulfillment Manager (versions 12.2.3 through 12.2.15) allows for unauthorized data access and modification. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. Notably, the vulnerability involves a 'scope change' (CVSS S:C), meaning a successful exploit can impact security components beyond the Service Fulfillment Manager itself. Successful attacks can result in complete unauthorized access to all accessible data or the ability to create, delete, or modify critical records. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle E-Business Suite Service Fulfillment Manager 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats