Junglewise Threat Intelligence

CVE-2026-60987: Oracle Project Portfolio Analysis data manipulation in Internal Operations

CVE-2026-60987 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle Project Portfolio Analysis. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability in the Internal Operations component of Oracle Project Portfolio Analysis could allow an authorized user with low-level permissions to compromise the system. This could lead to the unauthorized modification, creation, or deletion of critical business data, as well as unauthorized access to sensitive information. Such an exploit could disrupt project management operations and compromise the integrity of financial or portfolio data within the Oracle E-Business Suite.

Technical details

A vulnerability exists in the Internal Operations component of Oracle Project Portfolio Analysis (part of Oracle E-Business Suite). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to gain unauthorized read access to a subset of data and, more critically, unauthorized creation, deletion, or modification access to all or critical data within the component. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Project Portfolio Analysis 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats