Junglewise Threat Intelligence

CVE-2026-60986: Oracle Project Portfolio Analysis unauthorized data access in Internal Operations

CVE-2026-60986 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Project Portfolio Analysis. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in Oracle Project Portfolio Analysis, a component of the Oracle E-Business Suite used by organizations to manage and analyze project investments. An attacker with low-level user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the unauthorized viewing, modification, or deletion of critical project and financial information, potentially disrupting business operations and compromising data integrity.

Technical details

This vulnerability affects the Internal Operations component of Oracle Project Portfolio Analysis (versions 12.2.3 through 12.2.15). It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. The vulnerability allows an attacker to bypass intended access controls to achieve high confidentiality and integrity impacts. Successful exploitation enables the attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on critical data or all data accessible to the affected component. The CVSS 3.1 base score is 8.1, reflecting high impact on confidentiality and integrity with no impact on availability.

Affected products

  • Oracle Corporation Oracle Project Portfolio Analysis 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
  • 2026-07-21: disclosed

References

Related threats