Junglewise Threat Intelligence

CVE-2026-60951: Oracle Time and Labor data compromise in Internal Operations

CVE-2026-60951 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Time and Labor. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in Oracle Time and Labor, a component of the Oracle E-Business Suite used by organizations to manage employee hours and workforce data. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive records. This could lead to the theft, deletion, or modification of critical payroll and labor data, potentially disrupting business operations and compromising employee information.

Technical details

This vulnerability affects the Internal Operations component of Oracle Time and Labor within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged user authentication and network access via HTTP. An attacker can leverage this vulnerability to achieve unauthorized creation, deletion, or modification of all data accessible to the Time and Labor module. Additionally, it allows for complete unauthorized read access to critical data. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle Time and Labor 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle in the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed

References

Related threats