Vulnerability in Oracle E-Business Suite Internal Operations Product
CVE-2026-60886
7.6HIGH
What is CVE-2026-60886?
A vulnerability exists in Oracle Work in Process within the Oracle E-Business Suite that is easily exploitable by low-privileged attackers with network access via HTTP. This vulnerability requires human interaction to be successfully exploited, and while it is specifically tied to Oracle Work in Process, the effects can extend to other related products. Successful exploitation can lead to unauthorized access to sensitive data, enabling attackers to update, insert, or delete records in the system, thereby compromising data integrity and confidentiality.
Affected Version(s)
Oracle Work in Process 12.2.3 <= 12.2.15