Junglewise Threat Intelligence

CVE-2026-60973: Oracle E-Business Tax compromise in Internal Operations

CVE-2026-60973 · Severity: high · CVSS 7.8 · Published 2026-07-21

Technologies: Oracle E-Business Tax. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle E-Business Tax, a component of the Oracle E-Business Suite used by organizations to manage global tax automation and compliance. An attacker with basic access to the underlying system could exploit this flaw to gain full control over the tax management software. This could lead to the unauthorized modification of financial records, theft of sensitive tax data, or disruption of critical business operations.

Technical details

A vulnerability in the Internal Operations component of Oracle E-Business Tax (part of Oracle E-Business Suite) allows for a complete compromise of the application. The flaw is categorized as easily exploitable but requires the attacker to have local logon access to the infrastructure where the software executes. Successful exploitation grants the attacker high-impact access to confidentiality, integrity, and availability, effectively allowing a full takeover of the E-Business Tax product. The issue affects versions 12.2.3 through 12.2.15 and was addressed in the July 2026 Oracle Critical Patch Update.

Affected products

  • Oracle E-Business Tax 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats