Exploitable Vulnerability in Oracle E-Business Suite's Complex Maintenance and Repair Product
CVE-2026-60771
8.1HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 July 2026
What is CVE-2026-60771?
An exploitable API access vulnerability exists in Oracle E-Business Suite's Complex Maintenance, Repair and Overhaul product. This weakness allows a low-privileged attacker to access the network via HTTP, potentially leading to unauthorized creation, modification, or deletion of critical data. Affected versions range from 12.2.3 to 12.2.15, enabling attackers to manipulate access to crucial operational data across accessible services.
Affected Version(s)
Oracle Complex Maintenance, Repair and Overhaul 12.2.3 <= 12.2.15