Vulnerability in Oracle E-Business Suite Work in Process by Oracle
CVE-2026-60896

3.6LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60896?

A security vulnerability exists in Oracle E-Business Suite's Work in Process component, affecting versions 12.2.3 through 12.2.15. This vulnerability allows low-privileged attackers with access to the infrastructure where Oracle Work in Process operates to exploit it, potentially leading to unauthorized read access to sensitive data and the ability to execute a partial denial of service attack. The exploit's complexity is rated as high, making it challenging yet feasible for malicious actors to compromise the system, impacting both the confidentiality and availability of information.

Affected Version(s)

Oracle Work in Process 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.