Oracle E-Business Suite, Improper Authorization, CVE-2026-60984 (High) -DC-Jul2026-1188

Listen to this Post

CVE-2026-60984 is an improper authorization vulnerability identified in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite. The flaw resides within the Internal Operations component and affects supported versions from 12.2.3 through 12.2.15. The vulnerability is easily exploitable over a network via the HTTP protocol by a low-privileged attacker. Successful exploitation allows an attacker to perform unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of accessible data. The vulnerability is assigned a CVSS v3.1 Base Score of 7.1, indicating a High severity level. The CVSS vector string is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N, which highlights the network attack vector, low attack complexity, and the requirement of low privileges. The attack impacts confidentiality and integrity, with no availability impact. The vulnerability stems from a CWE-285 Improper Authorization weakness, where the product does not perform or incorrectly performs an authorization check. Technical details are not publicly available, and no exploit is known at this time. The vulnerability was published on July 21, 2026, and last modified on July 31, 2026. The estimated exploit price range is currently between $5,000 and $25,000. The EPSS score for this vulnerability is 0.00296, suggesting a low probability of exploitation in the wild. Oracle’s advisory is available, and it is recommended to apply the Critical Patch Update (CPU) as soon as possible.

DailyCVE Form:

Platform: Oracle E-Business Suite
Version: 12.2.3-12.2.15
Vulnerability: Improper Authorization
Severity: High (7.1)
date: 2026-07-21

Prediction: 2026-08-17

What Undercode Say:

Check Oracle E-Business Suite version
SELECT FROM PRODUCT_COMPONENT_VERSION WHERE UPPER(PRODUCT) LIKE '%E-BUSINESS%';
Check for affected Project Portfolio Analysis component
Consult Oracle Support for specific patch numbers
Apply Oracle Critical Patch Update (CPU) for July 2026

Exploit:

No public exploit is currently available. The vulnerability is easily exploitable over a network with low privileges. An attacker could potentially craft HTTP requests to bypass authorization checks within the Internal Operations component.

Protection:

Apply the Oracle Critical Patch Update (CPU) for July 2026, which addresses CVE-2026-60984. Restrict network access to the Oracle E-Business Suite instance. Monitor for unusual database activities and unauthorized data modifications.

Impact:

Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data. It also allows unauthorized read access to a subset of data. This can result in significant data integrity and confidentiality breaches.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top