Vulnerability in Oracle Learning Management Product by Oracle
CVE-2026-60945

7.3HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60945?

A vulnerability in the Oracle Learning Management component of Oracle E-Business Suite allows low-privileged attackers with network access via HTTP to exploit the system. The flaw facilitates unauthorized creation, deletion, or modification of data within the Oracle Learning Management, potentially leading to severe consequences for data confidentiality and integrity. Successful exploitation typically requires human interaction from an individual not affiliated with the attacker, raising significant concerns about unauthorized access and manipulation of critical data.

Affected Version(s)

Oracle Learning Management 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.