Junglewise Threat Intelligence

CVE-2026-60942: Oracle Service Fulfillment Manager data compromise in Fulfillment Engine

CVE-2026-60942 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Service Fulfillment Manager. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Service Fulfillment Manager, a component of the Oracle E-Business Suite used to manage and automate service orders. An attacker with basic user access can exploit this flaw over the network to gain full access to sensitive business data. This could lead to the unauthorized viewing, modification, or deletion of critical service fulfillment records, potentially disrupting business operations and compromising customer information.

Technical details

This vulnerability affects the Fulfillment Engine component of Oracle Service Fulfillment Manager (Oracle E-Business Suite). It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. The vulnerability does not require user interaction. Successful exploitation grants the attacker unauthorized 'create, delete, or modification' access as well as 'read' access to all data accessible by the Service Fulfillment Manager. The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N, indicating high confidentiality and integrity impacts but no impact on availability. Affected versions range from 12.2.3 through 12.2.15.

Affected products

  • Oracle Service Fulfillment Manager 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats