Junglewise Threat Intelligence

CVE-2026-60945: Oracle Learning Management unauthorized data access in Internal Operations

CVE-2026-60945 · Severity: high · CVSS 7.3 · Published 2026-07-21

Technologies: Oracle Learning Management. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Learning Management, a component of the Oracle E-Business Suite used by organizations to manage employee training and certifications. A low-privileged attacker can exploit this flaw to gain unauthorized access to sensitive training data or modify critical records. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a link, and could lead to a significant breach of data integrity and confidentiality within the learning platform.

Technical details

This vulnerability affects the Internal Operations component of Oracle Learning Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires network access via HTTP and low-level user privileges. The attack is dependent on human interaction (User Interaction: Required) from a person other than the attacker, suggesting a cross-site request forgery (CSRF) or similar UI-based attack vector. Successful exploitation allows an attacker to achieve high confidentiality and integrity impacts, including the unauthorized creation, deletion, or modification of all data accessible to the Learning Management module. Availability is not impacted. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Learning Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats