Vulnerability in Oracle E-Business Suite's Enterprise Asset Management Component
CVE-2026-60588

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60588?

An exploitable access control vulnerability exists in the Oracle E-Business Suite's Enterprise Asset Management component. A low-privileged attacker with network access through HTTPS can potentially compromise the system. This vulnerability allows unauthorized users to update, insert, or delete certain data accessible through the Oracle Enterprise Asset Management tool and read a subset of this data without proper authorization. Organizations using affected versions should apply the necessary patches to mitigate potential risks.

Affected Version(s)

Oracle Enterprise Asset Management 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.