Junglewise Threat Intelligence

CVE-2026-60960: Oracle SDP Number Portability compromise in Internal Operations

CVE-2026-60960 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle SDP Number Portability. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle SDP Number Portability, a tool used within Oracle E-Business Suite for managing telephone number porting. A low-privileged user with access to the underlying server infrastructure can exploit this flaw to take full control of the application. This could lead to unauthorized access to sensitive telecommunications data, service disruptions, and potential lateral movement to other connected business systems.

Technical details

This vulnerability affects the Internal Operations component of Oracle SDP Number Portability within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires local infrastructure logon with low-level privileges. The exploit results in a scope change (S:C), meaning a successful attack on this component can be used to impact other parts of the environment or additional products. The vulnerability allows for a complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H), effectively resulting in a total takeover of the affected product. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle SDP Number Portability 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD entry published

References

Related threats