Vulnerability in Oracle E-Business Suite Quality Component
CVE-2026-60855

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60855?

A vulnerability exists within the Oracle Quality component of the Oracle E-Business Suite, specifically affecting versions 12.2.3 through 12.2.15. This flaw makes it difficult for a low-privileged attacker with network access via HTTP to exploit the software. If successfully exploited, the vulnerability could allow unauthorized takeover of the Oracle Quality system. The risk this poses highlights the importance of maintaining up-to-date security measures and promptly applying provided patches to mitigate any potential threats.

Affected Version(s)

Oracle Quality 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.