Unauthenticated Access Vulnerability in Oracle Payments by Oracle
CVE-2026-60782

9.8CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-60782?

This vulnerability in the Oracle Payments component of Oracle E-Business Suite allows an unauthenticated attacker with network access via HTTP to gain control of Oracle Payments. The flaw could result in severe impacts affecting the confidentiality, integrity, and availability of the system, potentially leading to full takeover. Users operating on affected versions (12.2.3 through 12.2.15) should take immediate action to secure their systems to mitigate risks associated with this threat.

Affected Version(s)

Oracle Payments 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.