Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-60880: Oracle E-Business Suite Work in Process Takeover Risk (12.2.3-12.2.15)
CVE-2026-60880
CVE-2026-60880
Summary
Oracle E-Business Suite's Work in Process feature is at risk of being taken over by an attacker with internet access. This could happen if someone with malicious intentions can access your Work in Process system. To protect your system, update to a fixed version or apply the necessary patches.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| oracle corporation | oracle work in process | <= 12.2.15 |
Original title
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnera...
Original description
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
mitre CVSS3.1
9.8
Vulnerability type
CWE-284
Improper Access Control
CWE-306
Missing Authentication for Critical Function
- https://www.oracle.com/security-alerts/cpujul2026.html vendor-advisory
Published: 21 Jul 2026 · Updated: 25 Jul 2026 · First seen: 24 Jul 2026