Vulnerability in Oracle E-Business Suite Maintenance Component
CVE-2026-60717
5.4MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 July 2026
What is CVE-2026-60717?
The vulnerability affects the Oracle Complex Maintenance, Repair and Overhaul component of the Oracle E-Business Suite. It is caused by improper access control, enabling a low-privileged attacker with network access to exploit the system via HTTP. Successful exploitation may allow unauthorized actions, such as the ability to insert, update, or delete data, as well as unauthorized read access to sensitive information within the product. This presents significant risks to the confidentiality and integrity of accessible data managed by the affected component.
Affected Version(s)
Oracle Complex Maintenance, Repair and Overhaul 12.2.3 <= 12.2.15